| 

Chrome 19 released with tab syncing

  • Post author: Omid Farhang
  • Post published: May 17, 2012
  • Reading Time: 3 min
  • Word Count: 445 words

The H-Online: Google has announced that Chrome 19 is the new stable version of its open source based web browser. As usual, the browser sees a number of security fixes: this time there are seven high-severity fixes specifically for Chrome including various use-after-free and out-of-bounds errors. Two fixes with a wider impact than Chrome are also mentioned – a workaround for a Linux NVIDIA driver bug and an “off-by-one out-of-bounds” write in libxml. In all, $7500 was paid out in rewards to security researchers, and Google notes it has also paid out $9000 to researchers to stamp out bugs before they reached its stable channel. ...

Continue Reading Chrome 19 released with tab syncing

Microsoft Patch Tuesday more extensive than anticipated

  • Post author: Omid Farhang
  • Post published: May 10, 2012
  • Reading Time: 2 min
  • Word Count: 279 words

The H-Online: As previously announced, Microsoft has released seven bulletins to close a total of 23 vulnerabilities on its May Patch Tuesday. The total number of bulletins belies the scope of the patches, however, as the combined update MS12-034 closes various holes in numerous products. The reason for this is a critical hole in the code for processing TrueType fonts that was exploited by the Duqu spyware last year. The hole was closed in the Windows kernel on the December Patch Tuesday; however, Microsoft has since used a code scanner to track down the vulnerable code in numerous other components; among them is the gdiplus.dll library, which is used by various browsers to render web fonts. ...

Continue Reading Microsoft Patch Tuesday more extensive than anticipated

PHP patch quick but inadequate

  • Post author: Omid Farhang
  • Post published: May 5, 2012
  • Reading Time: 2 min
  • Word Count: 260 words

The H-Online: The updates to PHP versions 5.3.12 and 5.4.2 released on Thursday do not fully resolve the vulnerability that was accidentally disclosed on Reddit, according to the discoverer of the flaw. The bug in the way CGI and PHP interact with each other leads to a situation where attackers can execute code on affected servers. The issue remained undiscovered for eight years. The best protection at present is offered by setting up filter rules on the web server. However, the RewriteRule workaround described on PHP.net is also, according to security expert Christopher Kunz, inadequate. He suggests a slightly modified form of the rule as an alternative. ...

Continue Reading PHP patch quick but inadequate

Adobe Flash Player update closes critical object confusion hole

  • Post author: Omid Farhang
  • Post published: May 5, 2012
  • Reading Time: 2 min
  • Word Count: 214 words

The H-Online: Adobe has released a security advisory relating to an object confusion vulnerability which allows an attacker to crash the player or take control of an affected system. Adobe says that there are reports of this vulnerability being exploited in the wild as part of targeted email-based attacks which trick the user into clicking on a malicious file; this exploit only targets Flash Player on Internet Explorer on Windows, though the vulnerability exists on Windows, Mac OS X, Linux and Android versions of the player. ...

Continue Reading Adobe Flash Player update closes critical object confusion hole

Chrome 18 update closes high-risk security holes

  • Post author: Omid Farhang
  • Post published: May 1, 2012
  • Reading Time: 1 min
  • Word Count: 173 words

The H-Online: Google has released a new update to the stable 18.x branch of its Chrome web browser to close a number of security holes found in the application. The update, labelled 18.0.1025.168, addresses a total of five vulnerabilities, three of which are rated as “high severity” by the company. These include use-after-free problems in floating point handling and the XML parser; all of these bugs were detected using the AddressSanitizer. As part of its Chromium Security Vulnerability Rewards program, Google paid a security researcher by the name of “miaubiz”, who is number three in the company’s Security Hall of Fame, $1,000 for discovering and reporting one of the float handling problems. Two medium risk problems related to IPC validation and a race condition in sandbox IPC have also been corrected. ...

Continue Reading Chrome 18 update closes high-risk security holes

Mozilla to auto-upgrade Firefox 3.6 users to version 12

  • Post author: Omid Farhang
  • Post published: April 30, 2012
  • Reading Time: 2 min
  • Word Count: 278 words

H-Online: Soon, users running Firefox 3.6.x will start being automatically upgraded to the current version 12.0 release of the open source web browser. The plan to auto-update these users has been being discussed since the end of March, when Mozilla Release Manager Alex Keybl proposed the move on a Mozilla planning discussion thread. According to Keybl, Firefox 3.6.x users with updates enabled should start being upgraded in early May – the specific date has yet to be confirmed. The 3.6.x branch of Firefox, the first release of which arrived in January 2010, reached its end of life last week on 24 April; the last update to the 3.6 series was version 3.6.28 from early March. ...

Continue Reading Mozilla to auto-upgrade Firefox 3.6 users to version 12

DropBox 1.4 Released

  • Post author: Omid Farhang
  • Post published: April 27, 2012
  • Reading Time: 2 min
  • Word Count: 324 words

gHacks: Dropbox has just released a stable update that brings all desktop clients of the file synchronization and hosting service to 1.4. Feature-wise, it is not really a big change to previous versions, especially not so if you have been running experimental versions of the client before. When you look at the new feature set, you will notice that photo import from cameras, phones and SD cards is on top of that list. This is followed by a new batch upload and download option for files, and smaller cosmetic changes, like a fix for the missing camera upload icon on Mac OS X, or new tour screens for first time users. ...

Continue Reading DropBox 1.4 Released

PHP 5.4.1 and PHP 5.3.11 released

  • Post author: Omid Farhang
  • Post published: April 27, 2012
  • Reading Time: 1 min
  • Word Count: 189 words

The H-Online: The PHP developers have released the first update for PHP 5.4, the latest version of their popular scripting language, and an update to PHP 5.3, the older stable branch of the language. The developers say “All users of PHP are strongly encouraged to upgrade” to the new releases. PHP 5.4.1 has more than 20 bug fixes, including some related to security. One security bug concerned insufficient validating of the an upload name, which then led to corrupted $_FILES indices. Another notable change was open_basedir checks being added to readline_write_history and readline_read_history. ...

Continue Reading PHP 5.4.1 and PHP 5.3.11 released

Security improvements in Opera 12 beta

  • Post author: Omid Farhang
  • Post published: April 26, 2012
  • Reading Time: 2 min
  • Word Count: 388 words

The H-Online: A beta of version 12 of the Opera web browser has been released with privacy and security-focused improvements. Code-named “Wahoo”, the Opera 12.00 beta now runs plugins out-of-process and includes optimizations for better SSL handling. Running plugins in their own process not only improves the smoothness and stability of the browser but can limit the damage some plugin exploits can do. Privacy is enhanced with support for the “Do Not Track” (DNT) header, which is used to tell web sites that the browser user wishes to opt-out of online behavioral tracking. ...

Continue Reading Security improvements in Opera 12 beta

Microsoft Security Essentials 4.0 ready for download

  • Post author: Omid Farhang
  • Post published: April 25, 2012
  • Reading Time: 2 min
  • Word Count: 374 words

Cnet: Microsoft today made available for download a new release of its free anti-virus/anti-malware program for Windows PCs, Microsoft Security Essentials (MSE). The MSE 4.0 release is available via the Microsoft Download Center and the MSE Web site. (I learned of its availability from a post on Neowin today.) The latest version runs on Windows XP, Windows Vista, and Windows 7. The 4.0 version has been in beta since late 2011. As ZDNet sister site TechRepublic reported back in December 2011, Microsoft officials said the 4.0 release would include a streamlined interface; a renamed version of the SpyNet service (now slated to be known as Microsoft Active Protection Services); new automatic remediation functionality; and overall improved performance and detection capabilities. ...

Continue Reading Microsoft Security Essentials 4.0 ready for download