<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Vulnerability on Omid Farhang</title><link>https://omid.dev/tags/vulnerability/</link><description>Recent content in Vulnerability on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.161.1</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Fri, 09 Oct 2015 16:25:13 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/vulnerability/index.xml" rel="self" type="application/rss+xml"/><item><title>All the world's a Stagefright</title><link>https://omid.dev/2015/10/09/all-the-worlds-a-stagefright/</link><pubDate>Fri, 09 Oct 2015 16:25:13 +0000</pubDate><guid>https://omid.dev/2015/10/09/all-the-worlds-a-stagefright/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://omid.dev/images/2015/10/stagefright_bug_logo.png" alt="stagefright-android" /&gt;
&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s how security vulnerabilities are supposed to be handled. One, a researcher discovers an issue. Two, the people who make the software find a solution. And three, the solution is then made available, ideally by automatic update. That&amp;rsquo;s what Windows does, and what Apple does. It isn&amp;rsquo;t always as fast as it should be, but at least once the fix exists it&amp;rsquo;s available almost instantly.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s how it works with Android.&lt;/p&gt;</description></item><item><title>Apple closes QuickTime vulnerabilities on Windows</title><link>https://omid.dev/2013/05/23/apple-closes-quicktime-vulnerabilities-on-windows/</link><pubDate>Thu, 23 May 2013 20:01:51 +0000</pubDate><guid>https://omid.dev/2013/05/23/apple-closes-quicktime-vulnerabilities-on-windows/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2013/05/apple.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/05/apple.jpg" alt="apple" /&gt;
&lt;/a&gt;Apple has &lt;a href="http://prod.lists.apple.com/archives/security-announce/2013/May/msg00001.html"&gt;released&lt;/a&gt; a security update for its QuickTime media framework for Windows. Version 7.7.4 of the software closes 12 critical security holes causing memory corruption and buffer overflows when processing a number of media formats. The vulnerabilities affect Windows 7, Vista and XP SP2 or later and could be exploited to cause arbitrary code execution and application crashes.&lt;/p&gt;
&lt;p&gt;The vulnerabilities affected the playback of MP3, H.263, H.264, TeXML, JPEG, QTIF, Sorenson Video and FPX files as well as the handling of dref, enof and mvhd atoms within the program. All of the problems were reported by researchers working with HP&amp;rsquo;s Zero Day Initiative, five of them by Tom Gallagher and Paul Bates from Microsoft.&lt;/p&gt;</description></item><item><title>New Adobe Vulnerabilities Being Exploited in the Wild</title><link>https://omid.dev/2013/02/14/new-adobe-vulnerabilities-being-exploited-in-the-wild/</link><pubDate>Thu, 14 Feb 2013 21:20:00 +0000</pubDate><guid>https://omid.dev/2013/02/14/new-adobe-vulnerabilities-being-exploited-in-the-wild/</guid><description>&lt;p&gt;&lt;a href="http://lh5.ggpht.com/-otQzf_U6G6Q/UR1OFgU5RTI/AAAAAAAAHwg/7N4Pyc1bSnA/s1600-h/adobe%252520reader%25255B6%25255D.jpg" target="_blank"&gt;&lt;img title="adobe reader" border="0" alt="adobe reader" align="right" src="http://lh6.ggpht.com/-TS-def5Mp4I/UR1OHo6ClgI/AAAAAAAAHwo/L5mfaL8I6UU/adobe%252520reader_thumb%25255B4%25255D.jpg?imgmax=800" width="156" height="161" /&gt;&lt;/a&gt;Adobe posted a &lt;a href="http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.html"&gt;vulnerability report&lt;/a&gt; warning that vulnerabilities in Adobe Reader and Acrobat XI (11.0.1) and earlier versions are being exploited in the wild. Adobe is currently investigating this issue.&lt;/p&gt;
&lt;p&gt;According to the &lt;a href="http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html"&gt;FireEye blog&lt;/a&gt; posted earlier today, the malicious file arrives as a PDF file. Upon successful exploitation of the vulnerabilities, two malicious DLL files are dropped.&lt;/p&gt;
&lt;p&gt;Symantec detects the malicious PDF file as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-121708-1022-99"&gt;Trojan.Pidief&lt;/a&gt; and the two dropped DLL files as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-021914-2822-99"&gt;Trojan Horse&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Internet Explorer security hole: Use other browser</title><link>https://omid.dev/2012/09/18/internet-explorer-security-hole-use-other-browser/</link><pubDate>Tue, 18 Sep 2012 16:22:00 +0000</pubDate><guid>https://omid.dev/2012/09/18/internet-explorer-security-hole-use-other-browser/</guid><description>&lt;p&gt;&lt;strong&gt;TheTelegraph: Internet Explorer users might want to consider upgrading or switching to another browser after a massive security hole was discovered in Windows&amp;rsquo; native web browser.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-0Bv3ALH0CoQ/UFiYtKVSU0I/AAAAAAAAHc8/1JyUQDPOw20/s1600-h/internetexplorer9logo%25255B3%25255D.png" target="_blank"&gt;&lt;img title="internetexplorer9logo" border="0" alt="internetexplorer9logo" align="right" src="http://lh4.ggpht.com/-nXjmf0lXvVI/UFiYvRj-pOI/AAAAAAAAHdE/0J0YOZBFd4Y/internetexplorer9logo_thumb%25255B1%25255D.png?imgmax=800" width="144" height="148" /&gt;&lt;/a&gt;According to security forum, Rapid7 , Internet Explorer 7, 8 and 9 operating on Windows XP, Vista and Seven contains what is known as a “zero day exploit” which allows attackers to gain access to your personal data while you browse.&lt;/p&gt;
&lt;p&gt;The forum claimed the exploit would give cyber criminals “the same privileges as the current user”.&lt;/p&gt;</description></item><item><title>Adobe fixes ColdFusion security vulnerability</title><link>https://omid.dev/2012/09/12/adobe-fixes-coldfusion-security-vulnerability/</link><pubDate>Wed, 12 Sep 2012 16:59:00 +0000</pubDate><guid>https://omid.dev/2012/09/12/adobe-fixes-coldfusion-security-vulnerability/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-LkAOX83bLic/UFC4RXoJK-I/AAAAAAAAHZQ/A9AKnnXql7k/s1600-h/adobe_logo200.jpg" target="_blank"&gt;&lt;img title="adobe_logo200" border="0" alt="adobe_logo200" align="right" src="http://lh4.ggpht.com/-wQJsWLa234c/UFC4WzswABI/AAAAAAAAHaY/aQCGESlRA0I/adobe_logo200_thumb.jpg?imgmax=800" width="146" height="200" /&gt;&lt;/a&gt;h-Online: On the same day as Microsoft&amp;rsquo;s September Patch Tuesday, Adobe released &lt;a href="http://blogs.adobe.com/psirt/2012/09/security-update-released-for-coldfusion-10-and-earlier-apsb12-21.html"&gt;an update&lt;/a&gt; for &lt;a href="http://www.adobe.com/products/coldfusion-family.html"&gt;ColdFusion&lt;/a&gt; to close a security hole in its rapid web application development software. The hotfix for ColdFusion addresses a vulnerability (CVE-2012-2048), which the company rates as &lt;a href="http://www.adobe.com/support/security/severity_ratings.html"&gt;important&lt;/a&gt;, that could be exploited by a remote attacker to cause a denial-of-service (DoS) condition.&lt;/p&gt;
&lt;p&gt;According to Adobe, the unspecified error affects versions 8.0, 8.0.1, 9.0 to 9.0.2, and 10 of ColdFusion for Windows, Mac OS X and UNIX. Installing the provided hotfix corrects the problem; download links and installation instructions for each affected version are provided on the &lt;a href="http://helpx.adobe.com/coldfusion/kb/coldfusion-security-hotfix-apsb12-21.html"&gt;APSB12-21 technote page&lt;/a&gt;. All users are advised to download and apply the hotfix. Adobe credits UK developer &lt;a href="http://misterdai.yougeezer.co.uk/"&gt;David Boyer&lt;/a&gt; for finding and reporting the problem.&lt;/p&gt;</description></item><item><title>Oracle rushes out patch for critical 0-day Java exploit</title><link>https://omid.dev/2012/08/31/oracle-rushes-out-patch-for-critical-0-day-java-exploit/</link><pubDate>Fri, 31 Aug 2012 14:17:00 +0000</pubDate><guid>https://omid.dev/2012/08/31/oracle-rushes-out-patch-for-critical-0-day-java-exploit/</guid><description>&lt;p&gt;&lt;a href="http://lh6.ggpht.com/-wPwb8KpcqAo/UEDAS4TObCI/AAAAAAAAHR4/xIkTWQH65oM/s1600-h/Java%25255B3%25255D.jpg" target="_blank"&gt;&lt;img title="Java" border="0" alt="Java" align="right" src="http://lh3.ggpht.com/--isUL_TW-Wc/UEDAU9yTz2I/AAAAAAAAHSA/DkthqbTP-iw/Java_thumb%25255B6%25255D.jpg?imgmax=800" width="170" height="300" /&gt;&lt;/a&gt;TheRegister: In an uncommon break with its thrice-annual security update schedule, Oracle has released a patch for three Java 7 security flaws that have recently been targeted by web-based exploits.&lt;/p&gt;
&lt;p&gt;“Due to the high severity of these vulnerabilities, Oracle recommends that customers apply this Security Alert as soon as possible,” Eric Maurice, the company&amp;rsquo;s director of software security assurance, said in a &lt;a href="https://blogs.oracle.com/security/entry/security_alert_for_cve_20121"&gt;blog post&lt;/a&gt; published on Thursday.&lt;/p&gt;
&lt;p&gt;Maurice said that the vulnerabilities patched only affect Java running in browsers, and not standalone desktop Java applications or Java running on servers. According to Oracle&amp;rsquo;s &lt;a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html"&gt;official advisory&lt;/a&gt; on the flaws:&lt;/p&gt;</description></item><item><title>Java zero day vulnerability actively used in targeted attacks</title><link>https://omid.dev/2012/08/27/java-zero-day-vulnerability-actively-used-in-targeted-attacks/</link><pubDate>Mon, 27 Aug 2012 19:50:00 +0000</pubDate><guid>https://omid.dev/2012/08/27/java-zero-day-vulnerability-actively-used-in-targeted-attacks/</guid><description>&lt;p&gt;&lt;a href="http://www.zdnet.com/java-zero-day-vulnerability-actively-used-in-targeted-attacks-7000003233/" target="_blank"&gt;&lt;img title="Java" border="0" alt="Java" align="right" src="http://lh4.ggpht.com/-Z71qqXKB38g/UDvIjUWvYyI/AAAAAAAAHPQ/S_hkki2ZjnU/Java%25255B9%25255D.jpg?imgmax=800" width="175" height="300" /&gt;ZDNet&lt;/a&gt;: Security researchers from &lt;a href="http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html"&gt;FireEye&lt;/a&gt;, &lt;a href="http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/"&gt;AlienVault&lt;/a&gt;, and &lt;a href="http://www.deependresearch.org/2012/08/java-7-0-day-vulnerability-information.html"&gt;DeependResearch&lt;/a&gt; have intercepted targeted malware attacks utilizing the latest Java zero day exploit. The vulnerability affects Java 7 (1.7) Update 0 to 6. It does not affect Java 6 and below.&lt;/p&gt;
&lt;p&gt;Based on &lt;a href="https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day"&gt;related reports&lt;/a&gt;, researchers were able to reproduce the exploit on Windows 7 SP1 with Java 7 Update 6. There&amp;rsquo;s also &lt;a href="https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day"&gt;a Metasploit module&lt;/a&gt; available.&lt;/p&gt;
&lt;p&gt;Upon successful exploitation, the campaign drops &lt;a href="https://www.virustotal.com/file/09d10ae0f763e91982e1c276aad0b26a575840ad986b8f53553a4ea0a948200f/analysis/1346055031/"&gt;MD5: 4a55bf1448262bf71707eef7fc168f7d&lt;/a&gt; – detected by 28 out of 42 antivirus scanners as Gen:Trojan.Heur.FU.bqW@a4uT4@bb; Backdoor:Win32/Poison.E&lt;/p&gt;</description></item><item><title>Not so secure: Text messaging on iPhone can be hacked</title><link>https://omid.dev/2012/08/19/not-so-secure-text-messaging-on-iphone-can-be-hacked/</link><pubDate>Sun, 19 Aug 2012 14:07:00 +0000</pubDate><guid>https://omid.dev/2012/08/19/not-so-secure-text-messaging-on-iphone-can-be-hacked/</guid><description>&lt;p&gt;&lt;strong&gt;&lt;a href="http://lh6.ggpht.com/-o4dwmV4JJmc/UDDr_8SKtgI/AAAAAAAAHCM/HIL97pkDTsA/s1600-h/iPhone3GS%25255B5%25255D.jpg" target="_blank"&gt;&lt;img title="A hacker Friday revealed a security flaw that he claimed could make Apple’s iPhone particularly vulnerable to text message cheating." border="0" alt="A hacker Friday revealed a security flaw that he claimed could make Apple’s iPhone particularly vulnerable to text message cheating." align="right" src="http://lh3.ggpht.com/-wALB8CwfadM/UDDsBrXgOBI/AAAAAAAAHCU/hMp1ZLp-y5g/iPhone3GS_thumb%25255B3%25255D.jpg?imgmax=800" width="280" height="220" /&gt;&lt;/a&gt;FirstPost:&lt;/strong&gt; A hacker Friday revealed a security flaw that he claimed could make Apple’s iPhone particularly vulnerable to text message cheating.&lt;/p&gt;
&lt;p&gt;The flaw has existed since iPhone was first launched in 2007, and is still not solved in the beta version of iOS 6, the next operating system for iPhone, the hacker under the name “Pod2g” said in a blog post, reported &lt;em&gt;Xinhua.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>PostgreSQL patches XML flaws</title><link>https://omid.dev/2012/08/19/postgresql-patches-xml-flaws/</link><pubDate>Sun, 19 Aug 2012 08:51:00 +0000</pubDate><guid>https://omid.dev/2012/08/19/postgresql-patches-xml-flaws/</guid><description>&lt;p&gt;&lt;a href="http://lh5.ggpht.com/-_CvERcVioNM/UDCiAjUuQUI/AAAAAAAAG_k/BhHqmScL6wQ/s1600-h/PostgreSQL_Logo%25255B2%25255D.png" target="_blank"&gt;&lt;img title="PostgreSQL_Logo" border="0" alt="PostgreSQL_Logo" align="right" src="http://lh6.ggpht.com/-NQBd0Fjk1dQ/UDCiCi6_FMI/AAAAAAAAG_s/wB-EwOeaYfE/PostgreSQL_Logo_thumb.png?imgmax=800" width="150" height="117" /&gt;&lt;/a&gt;h-online: A flaw in the built-in XML functionality of &lt;a href="http://www.postgresql.org/"&gt;PostgreSQL&lt;/a&gt; (CVE-2012-3488) and another in its optional XSLT handling (CVE-2012-3489) have been patched, and the developers have &lt;a href="http://www.postgresql.org/about/news/1407/"&gt;released updated versions&lt;/a&gt; of the open source database with relevant fixes. The holes being patched are related to insecure use of the widely used libxml2 and libxslt open source libraries and the PostgreSQL developers advise anyone using those libraries to check their systems for similar problems.&lt;/p&gt;</description></item><item><title>LibreOffice vulnerable to multiple buffer overflows</title><link>https://omid.dev/2012/08/02/libreoffice-vulnerable-to-multiple-buffer-overflows/</link><pubDate>Thu, 02 Aug 2012 19:46:00 +0000</pubDate><guid>https://omid.dev/2012/08/02/libreoffice-vulnerable-to-multiple-buffer-overflows/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-lwgP4mg1MOI/UBrSFrn6MCI/AAAAAAAAGxg/iOJIdr37MZ0/s1600-h/LibreOffice%25255B2%25255D.png" target="_blank"&gt;&lt;img title="LibreOffice" border="0" alt="LibreOffice" align="right" src="http://lh3.ggpht.com/-e6Po0aP7wP4/UBrSHVjjxHI/AAAAAAAAGxo/lFPq4TUx1LQ/LibreOffice_thumb.png?imgmax=800" width="218" height="45" /&gt;&lt;/a&gt;h-online: Three weeks after &lt;a href="http://www.h-online.com/news/item/LibreOffice-3-5-5-update-improves-stability-1636972.html"&gt;releasing LibreOffice 3.5.5&lt;/a&gt;, &lt;a href="http://www.documentfoundation.org/"&gt;The Document Foundation&lt;/a&gt; has confirmed that security holes in earlier versions of the open source &lt;a href="http://www.libreoffice.org/"&gt;LibreOffice&lt;/a&gt; productivity suite can be exploited by attackers to compromise a victim&amp;rsquo;s system. According to the project&amp;rsquo;s &lt;a href="http://www.libreoffice.org/advisories/CVE-2012-2665/"&gt;security advisory&lt;/a&gt;, these include multiple heap-based buffer overflow vulnerabilities in the XML manifest encryption tag parsing code.&lt;/p&gt;
&lt;p&gt;Successful exploitation of the vulnerabilities could lead to the execution of arbitrary code on a system with the privileges of a local user. For an attack to be successful, a victim must first open a specially crafted Open Document Format (ODF) file. Versions up to and including LibreOffice 3.5.4 are affected; upgrading to version 3.5.5 or later fixes these problems. All users are advised to &lt;a href="http://www.libreoffice.org/download/"&gt;upgrade&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>QuickTime for Windows update plugs security holes</title><link>https://omid.dev/2012/05/17/quicktime-for-windows-update-plugs-security-holes/</link><pubDate>Thu, 17 May 2012 15:21:00 +0000</pubDate><guid>https://omid.dev/2012/05/17/quicktime-for-windows-update-plugs-security-holes/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-KjtBfYyOcz4/T7UQgYFY0kI/AAAAAAAAGAo/l4tbfWTyVxQ/s1600-h/Quicktime_120%25255B2%25255D.png"&gt;&lt;img title="Quicktime_120" border="0" alt="Quicktime_120" align="right" src="http://lh3.ggpht.com/-PkVmBfeFXdY/T7UQi356qRI/AAAAAAAAGAw/KDlTo4vnBPg/Quicktime_120_thumb.png?imgmax=800" width="120" height="121" /&gt;&lt;/a&gt;The H-Online: Version 7.7.2 of &lt;a href="http://www.apple.com/quicktime/"&gt;QuickTime&lt;/a&gt; for Windows has been released to address a total of 17 security vulnerabilities in the media player. According to Apple, these include integer, stack and buffer overflows, as well as memory corruption issues, all of which could be could exploited by an attacker to crash the application or execute arbitrary code on a victim&amp;rsquo;s system. For an attack to be successful, a user must first open a malicious web site or a specially crafted file.&lt;/p&gt;</description></item><item><title>RealPlayer update fixes security vulnerabilities</title><link>https://omid.dev/2012/05/17/realplayer-update-fixes-security-vulnerabilities/</link><pubDate>Thu, 17 May 2012 15:19:00 +0000</pubDate><guid>https://omid.dev/2012/05/17/realplayer-update-fixes-security-vulnerabilities/</guid><description>&lt;p&gt;&lt;a href="http://lh4.ggpht.com/-ZpK7OGIlX0E/T7UQAKJa_LI/AAAAAAAAGAY/FmEayK7ZLC0/s1600-h/realplayer_logo200%25255B2%25255D.png"&gt;&lt;img title="realplayer_logo200" border="0" alt="realplayer_logo200" align="right" src="http://lh5.ggpht.com/-_0NStkVzW3k/T7UQCUHur_I/AAAAAAAAGAg/Nu4kfKBVX-U/realplayer_logo200_thumb.png?imgmax=800" width="200" height="51" /&gt;&lt;/a&gt;The H-Online: &lt;a href="http://www.realnetworks.com/"&gt;RealNetworks&lt;/a&gt; is &lt;a href="http://service.real.com/realplayer/security/05152012_player/en/"&gt;warning&lt;/a&gt; users about multiple security vulnerabilities in its &lt;a href="http://www.real.com/realplayer"&gt;RealPlayer&lt;/a&gt; media player application for Windows; the company says that none of the, now fixed, holes are known to have been used to compromise systems.&lt;/p&gt;
&lt;p&gt;The released update, version 15.0.4.53 of RealPlayer, closes three security holes. One hole is related to ASM RuleBook parsing that could be exploited by an attacker to remotely execute arbitrary code, another is a memory corruption problem related to MP4 file handling in the QuickTime plugin used by RealPlayer, and the third is a buffer overrun in the Media parser.&lt;/p&gt;</description></item><item><title>Sniffer tool displays other people's WhatsApp messages</title><link>https://omid.dev/2012/05/13/sniffer-tool-displays-other-peoples-whatsapp-messages/</link><pubDate>Sun, 13 May 2012 22:06:00 +0000</pubDate><guid>https://omid.dev/2012/05/13/sniffer-tool-displays-other-peoples-whatsapp-messages/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-_y6ih_BTt2k/T7ApJb9to6I/AAAAAAAAF9g/hmIXjhzvFVw/s1600-h/whatsappsniffer%25255B4%25255D.png"&gt;&lt;img title="whatsappsniffer" border="0" alt="whatsappsniffer" align="right" src="http://lh5.ggpht.com/-qFL4blsjloE/T7ApOibKNiI/AAAAAAAAF9o/3zgQIOZmzBA/whatsappsniffer_thumb%25255B2%25255D.png?imgmax=800" width="201" height="240" /&gt;&lt;/a&gt;The H-Online: WhatsApp Sniffer is an app able to display messages from other WhatsApp users connected to the same network as the app user. The tool diverts all data traffic on, for example, a Wi-Fi network through the user&amp;rsquo;s smartphone and seeks out WhatsApp messages, which are transferred in plain text. All the user requires is a rooted Android smartphone.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www.whatsapp.com/"&gt;WhatsApp&lt;/a&gt; messaging service has established itself as an alternative to texting between smartphone users, because, unlike text messages, users only have to pay for data use. And if a user is in range of a free Wi-Fi point, then it is free to use.&lt;/p&gt;</description></item><item><title>Microsoft Patch Tuesday more extensive than anticipated</title><link>https://omid.dev/2012/05/10/microsoft-patch-tuesday-more-extensive-than-anticipated/</link><pubDate>Thu, 10 May 2012 09:43:00 +0000</pubDate><guid>https://omid.dev/2012/05/10/microsoft-patch-tuesday-more-extensive-than-anticipated/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-0mWP4hL3s38/T6uGtVCaFzI/AAAAAAAAF8I/azI-mt5ESXs/s1600-h/windows%252520update%25255B3%25255D.jpg"&gt;&lt;img title="windows update" border="0" alt="windows update" align="right" src="http://lh6.ggpht.com/-t62QOakM5Cg/T6uGuwHTgCI/AAAAAAAAF8Q/LsB6loffnKA/windows%252520update_thumb%25255B5%25255D.jpg?imgmax=800" width="170" height="220" /&gt;&lt;/a&gt;The H-Online: As previously announced, Microsoft has &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may"&gt;released&lt;/a&gt; seven bulletins to close a total of 23 vulnerabilities on its May Patch Tuesday. The total number of bulletins belies the scope of the patches, however, as the combined update &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034"&gt;MS12-034&lt;/a&gt; closes various holes in numerous products.&lt;/p&gt;
&lt;p&gt;The reason for this is a critical hole in the code for processing TrueType fonts that was exploited by the Duqu spyware last year. The hole was &lt;a href="http://www.h-online.com/news/item/13-pre-Christmas-patches-from-Microsoft-1394865.html"&gt;closed&lt;/a&gt; in the Windows kernel on the December Patch Tuesday; however, Microsoft has since used a code scanner to &lt;a href="http://blogs.technet.com/b/srd/archive/2012/05/08/ms12-034-duqu-ten-cve-s-and-removing-keyboard-layout-file-attack-surface.aspx"&gt;track down&lt;/a&gt; the vulnerable code in numerous other components; among them is the gdiplus.dll library, which is used by various browsers to render web fonts.&lt;/p&gt;</description></item><item><title>PHP patch quick but inadequate</title><link>https://omid.dev/2012/05/05/php-patch-quick-but-inadequate/</link><pubDate>Sat, 05 May 2012 19:25:00 +0000</pubDate><guid>https://omid.dev/2012/05/05/php-patch-quick-but-inadequate/</guid><description>&lt;p&gt;&lt;a href="http://lh6.ggpht.com/-Cu0J300RYng/T6V3sHhQsrI/AAAAAAAAF50/eNMs7kndTd8/s1600-h/php%25255B2%25255D.png"&gt;&lt;img title="php" border="0" alt="php" align="right" src="http://lh4.ggpht.com/-AYBT2UispLs/T6V3uFbK68I/AAAAAAAAF58/T13rvx5zFWQ/php_thumb.png?imgmax=800" width="180" height="95" /&gt;&lt;/a&gt;The H-Online: The &lt;a href="http://www.php.net/archive/2012.php#id2012-05-03-1"&gt;updates&lt;/a&gt; to PHP versions 5.3.12 and 5.4.2 released on Thursday do not fully resolve the &lt;a href="http://www.h-online.com/news/item/Critical-open-hole-in-PHP-creates-risks-Update-2-1567532.html"&gt;vulnerability&lt;/a&gt; that was accidentally disclosed on Reddit, &lt;a href="http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/"&gt;according&lt;/a&gt; to the discoverer of the flaw. The bug in the way CGI and PHP interact with each other leads to a situation where attackers can execute code on affected servers. The issue remained undiscovered for eight years.&lt;/p&gt;
&lt;p&gt;The best protection at present is offered by setting up filter rules on the web server. However, the RewriteRule workaround described on PHP.net is also, according to security expert Christopher Kunz, inadequate. He suggests a slightly modified form of the rule as an &lt;a href="http://www.php-security.net/archives/11-Mitigation-for-CVE-2012-1823-CVE-2012-2311.html"&gt;alternative&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Firefox WebSocket bug compromises Tor anonymity</title><link>https://omid.dev/2012/05/03/firefox-websocket-bug-compromises-tor-anonymity/</link><pubDate>Thu, 03 May 2012 14:27:00 +0000</pubDate><guid>https://omid.dev/2012/05/03/firefox-websocket-bug-compromises-tor-anonymity/</guid><description>&lt;p&gt;The current versions of the &lt;a href="https://www.torproject.org/projects/torbrowser.html.en"&gt;Tor Browser Bundle&lt;/a&gt; (TBB) include &lt;a href="https://blog.torproject.org/blog/firefox-security-bug-proxy-bypass-current-tbbs"&gt;a bug&lt;/a&gt; that makes it possible for information about visited web sites to leak out of the anonymising layer. On version 2.2.35-9 of TBB for Windows and version 2.2.35-10 for Mac OS X and Linux, the included version of Firefox does not send DNS requests over the &lt;a href="https://www.torproject.org/"&gt;Tor&lt;/a&gt; network if the browser is using the &lt;a href="https://en.wikipedia.org/wiki/WebSocket"&gt;WebSocket&lt;/a&gt; protocol. This means that an attacker listening in on the connection will be able to identify the servers the user is visiting.&lt;/p&gt;</description></item><item><title>Skype divulges user IP addresses</title><link>https://omid.dev/2012/04/30/skype-divulges-user-ip-addresses/</link><pubDate>Mon, 30 Apr 2012 17:36:00 +0000</pubDate><guid>https://omid.dev/2012/04/30/skype-divulges-user-ip-addresses/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-vNLSJyvb0pw/T57GX25RrHI/AAAAAAAAFxs/3xDJMiD49B0/s1600-h/skype_logo200%25255B2%25255D.png"&gt;&lt;img title="skype_logo200" border="0" alt="skype_logo200" align="right" src="http://lh4.ggpht.com/-7EPh_zAX_yI/T57GZ-WuvwI/AAAAAAAAFx4/r0qGoHHpA7w/skype_logo200_thumb.png?imgmax=800" width="200" height="88" /&gt;&lt;/a&gt;The H-Online: According to a &lt;a href="http://skype-open-source.blogspot.com/2012/04/skype-user-ip-address-disclosure.html"&gt;blog post&lt;/a&gt;, a modified version of the &lt;a href="http://www.skype.com/"&gt;Skype&lt;/a&gt; VoIP software can be used to easily find out the &lt;a href="http://en.wikipedia.org/wiki/IP_address"&gt;IP address&lt;/a&gt; of any valid Skype user. No contact has to be made with the user in order to get the information. This IP could then be used to find out other personal details about the user, such as their location or even their employer.&lt;/p&gt;
&lt;p&gt;With a certain registry key, the manipulated version of Skype will create a log file with information including other users&amp;rsquo; external and internal IP addresses. These IPs can be retrieved simply by opening up a user&amp;rsquo;s profile with the Skype client. In a test conducted by The H&amp;rsquo;s associates at heise Security, the log file always showed the correct IPs – and when a user was logged in with multiple clients, the IP addresses for all the clients were visible.&lt;/p&gt;</description></item><item><title>Security vulnerability in NVIDIA's proprietary Linux drivers fixed</title><link>https://omid.dev/2012/04/12/security-vulnerability-in-nvidias-proprietary-linux-drivers-fixed/</link><pubDate>Thu, 12 Apr 2012 19:01:00 +0000</pubDate><guid>https://omid.dev/2012/04/12/security-vulnerability-in-nvidias-proprietary-linux-drivers-fixed/</guid><description>&lt;p&gt;&lt;a href="http://lh6.ggpht.com/-gtXFjG4z3M8/T4cfj6WzceI/AAAAAAAAFeg/4uqTaeWiYlQ/s1600-h/NVIDIA_logo200%25255B3%25255D.png"&gt;&lt;img title="NVIDIA_logo200" border="0" alt="NVIDIA_logo200" align="right" src="http://lh5.ggpht.com/-942xaZtdEac/T4cfmI6tD2I/AAAAAAAAFeo/-aybmQ6NL-c/NVIDIA_logo200_thumb%25255B1%25255D.png?imgmax=800" width="150" height="111" /&gt;&lt;/a&gt;The H-Online: A new version of NVIDIA&amp;rsquo;s &lt;a href="http://www.nvidia.com/object/unix.html"&gt;proprietary UNIX graphics drivers&lt;/a&gt; for Linux, Solaris and FreeBSD fixes a &lt;a href="http://nvidia.custhelp.com/app/answers/detail/a_id/3109"&gt;security vulnerability&lt;/a&gt; (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0946"&gt;CVE-2012-0946&lt;/a&gt;) that allowed attackers to read and write arbitrary system memory in order to, for example, obtain root privileges. To take advantage of the vulnerability, an attacker must have access permission for some device files – which, for systems with these drivers, is typically the case for users who can launch a graphical interface as 3D acceleration and some other features cannot be used otherwise.&lt;/p&gt;</description></item><item><title>Microsoft and Adobe to address critical vulnerabilities on Patch Tuesday</title><link>https://omid.dev/2012/04/07/microsoft-and-adobe-to-address-critical-vulnerabilities-on-patch-tuesday/</link><pubDate>Sat, 07 Apr 2012 20:12:00 +0000</pubDate><guid>https://omid.dev/2012/04/07/microsoft-and-adobe-to-address-critical-vulnerabilities-on-patch-tuesday/</guid><description>&lt;p&gt;The H-Online: The Tuesday after the Easter weekend, 10 April, is set to be a busy one for system administrators as Microsoft and Adobe have sent out notifications that they will both be issuing fixes for critical vulnerabilities in their products.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://lh6.ggpht.com/-JCwenj0lqXM/T4CYkGYBwwI/AAAAAAAAFcY/3cfuqU5kma8/s1600-h/windows%252520update%25255B6%25255D.jpg"&gt;&lt;img title="windows update" border="0" alt="windows update" align="right" src="http://lh4.ggpht.com/-ihEpQdTcggs/T4CYl5NIf5I/AAAAAAAAFcg/_f5gDUEVaqw/windows%252520update_thumb%25255B8%25255D.jpg?imgmax=800" width="83" height="98" /&gt;&lt;/a&gt;Microsoft&amp;rsquo;s &lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr"&gt;April notification&lt;/a&gt; says there will be four critical advisories concerning Microsoft Windows, Internet Explorer, .NET Framework, Office, SQL Server, Microsoft Server and Developer tools, which all lead to remote code execution. A fifth remote code execution vulnerability in Office is marked as important, as is a sixth information disclosure issue in Microsoft&amp;rsquo;s Forefront United Access Gateway. The critical bulletins will affect all versions of Windows, from Windows XP SP3 to Windows Server 2008R2. One critical bulletin for Internet Explorer covers IE 6, 7, 8 and 9&lt;/p&gt;</description></item><item><title>Google Chrome fixes seven high-risk vulnerabilities</title><link>https://omid.dev/2012/04/06/google-chrome-fixes-seven-high-risk-vulnerabilities/</link><pubDate>Fri, 06 Apr 2012 20:28:00 +0000</pubDate><guid>https://omid.dev/2012/04/06/google-chrome-fixes-seven-high-risk-vulnerabilities/</guid><description>&lt;p&gt;&lt;a href="http://lh6.ggpht.com/-oBFEuHM2jXA/T39Ky857ckI/AAAAAAAAFbE/2TO8aqTx9KY/s1600-h/new-chrome-logo%25255B3%25255D.png"&gt;&lt;img title="new-chrome-logo" border="0" alt="new-chrome-logo" align="right" src="http://lh3.ggpht.com/-21hvbRz1hww/T39K4ZcSLwI/AAAAAAAAFbM/O1ibokDSomQ/new-chrome-logo_thumb%25255B1%25255D.png?imgmax=800" width="128" height="125" /&gt;&lt;/a&gt;The H-Online: Google &lt;a href="http://googlechromereleases.blogspot.co.uk/2012/04/stable-and-beta-channel-updates.html"&gt;has announced updates&lt;/a&gt; to the Stable and Beta channels of their Chrome browser, fixing several bugs and twelve security vulnerabilities. Seven of the twelve security fixes were classed as high-risk problems and Google paid a total of $6000 to the researchers who discovered the bugs.&lt;/p&gt;
&lt;p&gt;The update also includes a new version of the bundled Flash Player. Adobe have revised the Flash Player advisory from the &lt;a href="http://www.h-online.com/news/item/Patch-for-Adobe-Flash-closes-two-critical-security-holes-1486334.html"&gt;end of March&lt;/a&gt; to include fixes for a Chrome/Flash only pair of memory corruption issues listed as CVE-2012-0724 and CVE-2012-0725. Given that these issues only affect Chrome and Chrome manages its own update, it is unlikely that Adobe will be reissuing or updating the advisory or patches for other browsers and platforms.&lt;/p&gt;</description></item></channel></rss>