dcinematools.com

Tuesday
May 22nd
Text size
  • Increase font size
  • Default font size
  • Decrease font size
Home Security Constant Alertness Current Security Updates – 09/09

Current Security Updates – 09/09

email print PDF

Charles Flynn Reports: Security Updates Abound

Please let us know if you see updates that we should inform the community about. This is what we have had recently:

Let's take a look at those patches in Firefox 3.5.3, since 3.5 was released:

Security Advisories for Firefox 3.5

Impact key: [The circles and arrows looks prettier on the original site - link above - Ed]

  • Critical: Vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.
  • High: Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.
  • Moderate: Vulnerabilities that would otherwise be High or Critical except they only work in uncommon non-default configurations or require the user to perform complicated and/or unlikely steps.
  • Low: Minor security vulnerabilities such as Denial of Service attacks, minor data leaks, or spoofs. (Undetectable spoofs of SSL indicia would have "High" impact because those are generally used to steal sensitive data intended for other sites.)
Fixed in Firefox 3.5.3
Critical: MFSA 2009-51 Chrome privilege escalation with FeedWriter
MFSA 2009-50 Location bar spoofing via tall line-height Unicode characters
Critical: MFSA 2009-49 TreeColumns dangling pointer vulnerability
Critical: MFSA 2009-47 Crashes with evidence of memory corruption (rv:1.9.1.3/1.9.0.14)

Fixed in Firefox 3.5.2
Critical: MFSA 2009-46 Chrome privilege escalation due to incorrectly cached wrapper
Critical: MFSA 2009-45 Crashes with evidence of memory corruption (rv:1.9.1.2/1.9.0.13)
MFSA 2009-44 Location bar and SSL indicator spoofing via window.open() on invalid URL
MFSA 2009-38 Data corruption with SOCKS5 reply containing DNS name longer than 15 characters

Fixed in Firefox 3.5.1
Critical: MFSA 2009-41 Corrupt JIT state after deep return from native function
Critical: MFSA 2009-35 Crash and remote code execution during Flash player unloading

Fixed in Firefox 3.5
Critical: MFSA 2009-43 Heap overflow in certificate regexp parsing
Critical: MFSA 2009-42 Compromise of SSL-protected communication
MFSA 2009-40 Multiple cross origin wrapper bypasses
Critical: MFSA 2009-39 setTimeout loses XPCNativeWrappers
Critical: MFSA 2009-37 Crash and remote code execution using watch and __defineSetter__ on SVG element
Critical: MFSA 2009-36 Heap/integer overflows in font glyph rendering libraries
Critical: MFSA 2009-34 Crashes with evidence of memory corruption (rv:1.9.1/1.9.0.12)

That's a heap of Critical - Message is: Stay on top of Firefox. Stay on top of every freakin' piece of software you have, for certainly, the blackhats are.


Nine patches for Microsoft's next Patch Tuesday | IT PRO By Nicole Kobie, 7 Aug 2009 at 10:26

 

Microsoft will issue nine security patches next Tuesday, as part of its monthly patching cycle.

The majority affect various versions of Windows. Five are seen as critical by Microsoft, with the other three rated important. One critical patch also affects Client for Mac, while one of the important patches is for the .NET Framework.

The last bulletin is for a flaw in Microsoft Office's Web Components, which was reported last month. The critical patch affects Microsoft Office, Visual Studio, ISA Server and BizTalk.

Paul Henry, security and forensic analyst at Lumension, said: “After a summer of heavier-than-normal Patch Tuesdays, the last thing IT workers need next Tuesday is yet another large batch of patches from Microsoft."

He warned that anyone using Microsoft's ISA server should pay attention to this patch. “One of Microsoft’s security products, Internet Security and Acceleration (ISA) server, appears to have a hole that’s critical on all versions," he said.

"Therefore, companies that are actively using this product as part of their security infrastructure will need to patch this vulnerability immediately."

The patch will be delivered by autoupdate or be available to download on 11 August.

Microsoft issued a pair of out-of-band patches last week, to fix flaws in Internet Explorer and Visual Studio.

Apple updates Mac OS | IT PRO By Nicole Kobie, 6 Aug 2009 at 11:07

Apple has released the Mac OS X 10.5.8 update, patching a few issues in its Leopard operating system,  one month before the new 10.6 Snow is expected to be released.

Aside from general stability issues, the update fixes problems with joining AirPort networks, monitor resolution settings and Bluetooth reliability with peripheral devices like printers. The update also fixes an error which slowed startup time and another which affected imports of large movie or photo files.

The Mac OS X 10.5.8 update includes the latest version of Safari and all recent security patches.

 

GarageBand 5.1 puts lid back on cookie jar - News - The H Security: News and features 6 August 2009

Apple has released an update for its GarageBand application, addressing a security issue that could allow third parties or advertisers to track a user's web activity. When a user opens the GarageBand application, it automatically changes Safari's security preferences to always accept cookies, rather than the default setting of "Only from sites I visit".

The change means that users may no longer be blocking any third-party cookies which advertisers can use to track their online activity.     [Read more data at H Security source material above.]

Naming trick opens mail servers - News - The H Security: News and features 6 August 2009

A number of Vietnamese spam sources are currently attracting attention because the spammers have equipped the relevant hosts with DNS pointer records called "localhost". As a result, IP addresses like 123.27.3.81, 222.252.80.188 or 123.16.13.188 produce this name when a reverse look-up occurs. The problem is caused by badly configured Domain Name Systems, as "localhost" should generally translate to a single IP address – 127.0.0.1 ...

...

Mail server operators must make sure they avoid falling victim to this trick. For example, they can make relays only available from local IP addresses and not identify clients by reverse look-up DNS names. Normal open relay tests don't produce an alert in this case, because the test client usually isn't called "localhost". Several vulnerable mail servers have already been added to the iX blacklist. In addition to blacklisting, the operators of open relays potentially face having to pay damages to spam or malware recipients. [Read more data at H Security source material above.]

Firefox patches Black Hat SSL encryption vulnerability | IT PRO By Asavin Wattanajantra, 4 Aug 2009 at 11:23

Firefox has released version 3.5.2, a patch closing four critical vulnerabilities - one of which was a serious SSL encryption flaw discovered at the recent Black Hat conference in Las Vegas

The flaw is described in more detail here, but as Mozilla said in an advisory, it basically meant that attackers could have obtained certificates that could intercept and alter encrypted information between client and server, such as bank account transactions.

...

The other three vulnerabilities were also critical. This meant that attackers could have taken advantage by running code and installing software on a user’s computer even if they were just browsing normally.

[Story is severely edited...see the original.]

Latest Videos in Security

Video: Mobile security threats and Mac complacency Play Video: Mobile security threats and Mac complacency Play

Part two: Eugene Kaspersky, chief executive and founder of Kaspersky Lab, talks about the increasing security threats mobile users are facing.

 

Showbiz Podcast

There are many who know more about movie equipment than they do about all the fluff and glamor which pays for it all. Showbiz...

Free International DCinema Business Directory...How To...

DCinemaTools.com is pleased to have added a free feature called The Business Directory. Free to use, free to enter. If a per...

  • Showbiz Podcast

    Tuesday, 31 January 2012 15:11
  • Free International DCinema Business Directory...How To...

    Friday, 27 January 2012 22:24
DCinemaToday's Latest:

The Death of Silver Screens~! Vive la France

In May of 2002, the Attack of the Clones (Star Wars II) was released after a great effort by George Lucas. He encouraged cine...

DCinema Projectionist and Tech Survey – November 2011

Hello; a friend is giving a presentation at Camera Image Conference at the end of November 2011. We would apprecia...

3Questions: OpenDCP – Now with GUI

The dream of creating DCPs for local commercials and film festivals by artists using simple yet affordable tools just took a ...

3Questions on HI/VI Issues – European Union of the Deaf

There are several groups who represent the varied and specific interests of the community of people with disabilities in...

23 degrees...half the light. 3D What?

3D Luminance Issues—Photopic, barely. Mesopic, often. Scotopic? Who knows...?  We don't mean to be picking on the good ...

The State of Digital Cinema - April 2010 - Part Zero

This document is Part 0 of an multipart article that details with the basics of today's transition from film-based cinema to ...

What Is A Projectionist? In The Digital Age

Marketing Guru Adrian Weidmann says, "Always Solve For Why". In the Digital Cinema Age there are several more Quality Control...

The State of Digital Cinema - April 2010 Part Two

Part I of this series ended with generalities about where DCinema has been and how it got here. Since the series is written...

The State of Digital Cinema - April 2010 | Part One

As it is in many fields, the world of cinema involves a broad reach of talent and technology that begins with an artistic i...

Scotopic Issues with 3D, and Silver Screens

SMPTE and DCI specs notwithstanding, measuring an auditorium is an art, not a science. Even a non-silver screen with gain is ...

  • The Death of Silver Screens~! Vive la France

    Tuesday, 13 March 2012 00:00
  • DCinema Projectionist and Tech Survey – November 2011

    Thursday, 10 November 2011 01:48
  • 3Questions: OpenDCP – Now with GUI

    Wednesday, 27 April 2011 11:06
  • 3Questions on HI/VI Issues – European Union of the Deaf

    Wednesday, 12 January 2011 15:06
  • 23 degrees...half the light. 3D What?

    Monday, 16 August 2010 22:27
  • The State of Digital Cinema - April 2010 - Part Zero

    Monday, 26 April 2010 05:44
  • What Is A Projectionist? In The Digital Age

    Thursday, 07 July 2011 09:50
  • The State of Digital Cinema - April 2010 Part Two

    Monday, 26 April 2010 05:39
  • The State of Digital Cinema - April 2010 | Part One

    Thursday, 22 April 2010 12:53
  • Scotopic Issues with 3D, and Silver Screens

    Tuesday, 13 July 2010 18:20

Quick Links

DCinemaToday
Only the news that really counts - plus all the contacts with all the companies
SMPTE
Spanning all the Motion Picture and Television Technologies
ISDCF
An InterSociety Group Dealing with Digital Cinema
 
The European Digital Cinema Forum
 
National Association of Theater Owners
Flash Version Check
UPGRADE YOUR FLASH NOW~!

RSS Feed; Entire Journal

DCinemaTools | Like Tangents In The Rain DCinemaTools | Like Tangents In The Rain

DCinema Events

May 2012
S M T W T F S
29 30 1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31 1 2
June 2012
S M T W T F S
27 28 29 30 31 1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30

Coming Events

Tue May 29
Show Canada 2012
Mon Jun 04
ISDCF June Plugfest
Wed Jun 06 @10:30 - 03:00PM
ISDCF June after Plugfest
Sat Jun 09
infoComm12
Mon Jun 18
CineEurope
Sun Jul 15 @08:00 - 05:00PM
ICTA Annual Seminar Series

Events Search