Showing posts with label patches. Show all posts
Showing posts with label patches. Show all posts

Thursday, 31 October 2013

Mozilla releases 10 patches, five critical, for Firefox

Mozilla released 10 patches for three versions of its Firefox browser on Tuesday, five of which are considered critical and could be used to remotely install malicious code.

The U.S. Computer Emergency Readiness Team warned that the problems "could allow a remote attacker to execute arbitrary code, bypass intended access restrictions, cause a denial-of-service condition or obtain sensitive information."

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

The Mozilla products affected are Firefox 25, Firefox ESR 24.1, Firefox Extended Support Release (ESR) 17.0.10, Thunderbird 24.1, Thunderbird ESR 17.0.10, and Seamonkey 2.22.

Among the flaws fixed were several memory safety bugs in the browser engine, which is also in Mozilla's Thunderbird email client and Seamonkey, a suite of applications and web development tools.

Those bugs, tagged as update MFSA 2013-93, "showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code," according to Mozilla's advisory.

The other four critical vulnerabilities could cause potentially exploitable crashes, Mozilla said.

One of the vulnerabilities given a "high" risk rating, MFSA 2013-99, could divulge information on a computer's local system. A security researcher, Cody Crews, discovered "a method to append an iframe into an embedded PDF object rendered with the chrome privileged PDF.js."

"This can used to bypass security restrictions to load local or chrome privileged files and objects within the embedded PDF object," Mozilla wrote.

In August, the TOR project warned that a vulnerability in Firefox ESR may have been used to collect information on computers visiting websites configured as TOR hidden services.

TOR, short for The Onion Router, is a system that allows for more anonymous browsing by routing encrypted requests for websites through servers worldwide. The TOR Project distributes a Browser Bundle, which includes Firefox for browsing with TOR.

The vulnerability could have facilitated the execution of remote code, but instead may have been used to collect the hostname and MAC address of Windows computers, it said. The TOR Project typically updates its browser bundle package quickly after Mozilla releases new patches.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk.


View the original article here

Mozilla releases 10 patches, five critical, for Firefox

IDG News Service - Mozilla released 10 patches for three versions of its Firefox browser on Tuesday, five of which are considered critical and could be used to remotely install malicious code.

The U.S. Computer Emergency Readiness Team warned that the problems "could allow a remote attacker to execute arbitrary code, bypass intended access restrictions, cause a denial-of-service condition or obtain sensitive information."

The Mozilla products affected are Firefox 25, Firefox ESR 24.1, Firefox Extended Support Release (ESR) 17.0.10, Thunderbird 24.1, Thunderbird ESR 17.0.10, and Seamonkey 2.22.

Among the flaws fixed were several memory safety bugs in the browser engine, which is also in Mozilla's Thunderbird email client and Seamonkey, a suite of applications and web development tools.

Those bugs, tagged as update MFSA 2013-93, "showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code," according to Mozilla's advisory.

The other four critical vulnerabilities could cause potentially exploitable crashes, Mozilla said.

One of the vulnerabilities given a "high" risk rating, MFSA 2013-99, could divulge information on a computer's local system. A security researcher, Cody Crews, discovered "a method to append an iframe into an embedded PDF object rendered with the chrome privileged PDF.js."

"This can used to bypass security restrictions to load local or chrome privileged files and objects within the embedded PDF object," Mozilla wrote.

In August, the TOR project warned that a vulnerability in Firefox ESR may have been used to collect information on computers visiting websites configured as TOR hidden services.

TOR, short for The Onion Router, is a system that allows for more anonymous browsing by routing encrypted requests for websites through servers worldwide. The TOR Project distributes a Browser Bundle, which includes Firefox for browsing with TOR.

The vulnerability could have facilitated the execution of remote code, but instead may have been used to collect the hostname and MAC address of Windows computers, it said. The TOR Project typically updates its browser bundle package quickly after Mozilla releases new patches.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Windows XP infection rate may jump 66% after patches end in April

Computerworld - Microsoft yesterday again but the scare into Windows XP users, telling them that after April 8, 2014, the chance that malware will infect their PCs could jump by two-thirds.

The claim, made by Tim Rains, director of Microsoft's Trustworthy Computing group, came on the heels of the release of the company's twice-annual Security Intelligence Report (download PDF).

Following up on comments he made in August, Rains again warned Windows XP stragglers to expect an increase in attacks when the aged operating system exits support in five months.

"After end of support, attackers will have an advantage over defenders who continue to run Windows XP," Rains asserted in a Tuesday post to a company blog. "After April next year, when we release monthly security updates for supported versions of Windows, attackers will try and reverse engineer them to identify any vulnerabilities that also exist in Windows XP. If they succeed, attackers will have the capability to develop exploit code to take advantage of them."

Rains then went a step further, and cited statistics from Microsoft's own telemetry-gathering efforts to give customers an idea of the increased threat after support ends.

"We have already had a glimpse into what happens when a Windows XP-based platform goes out of support," Rains added. "In the two years after Windows XP Service Pack 2 went out of support, its malware infection rate was 66% higher than Windows XP Service Pack 3 -- the last supported version of Windows XP."

Support for Windows XP Service Pack 2 (SP2) ended in July 2010, a little over two years after the release of XP SP3.

In a chart accompanying his comments, Rains showed the higher infection rate of Windows XP SP2 when compared to SP3. The two started out with similar infection rates, but began to diverge in the first quarter of 2011, with the largest gap in Q4 of that year. Since then, the difference between the two has narrowed: In the fourth quarter of 2012, the latest shown in the chart, the gap appeared to be approximately four computers per thousand -- 12 for SP3 versus 16 for SP2 -- representing a 33% increase in the latter's infection rate.

While there could be other reasons for the different infection rates, including lack of up-to-date security software, Rains' implied assumption was that it was because XP SP2 had not been patched -- because it could not be -- while XP SP3 had been.

Microsoft has been extremely blunt about the danger customers will face next year after Windows XP support vanishes, belittling the creaky OS's security prowess, even attacking it at times. That's unusual. Microsoft's usual tactic is to simply ignore an older operating system, as it does Windows Vista, the flop that now accounts for just 4% of all Windows PCs.

"You never heard Microsoft tell Windows Millennium users that they had to upgrade," said Michael Cherry, an analyst with Directions on Microsoft, referring to a September 2000 edition that quickly vanished after XP's appearance a year later.

But things are different this time around.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here