Thursday, March 3, 2011

Firefox, Thunderbird, iTunes, Adobe Reader, Adobe Flash Player, Foxit Reader all patched

In addition to Windows Updates this month, system admins have their hands full patching lots of Internet-touching software:
  • Apple plugs 57 major security holes in iTunes | ZDNet
    If you use Apple’s iTunes software — whether on Windows or Mac OS X — it’s important that you immediately apply the latest software update.

    Apple has shipped iTuens [sic] 10.2 as a highly-critical patch to cover a whopping 57 security vulnerabilities, some serious enough to allow hackers to take complete control of a vulnerable machine.
  • Adobe - Security Bulletins: APSB11-02 - Security update available for Adobe Flash Player
    Critical vulnerabilities have been identified in Adobe Flash Player 10.1.102.64 and earlier versions for Windows, Macintosh, Linux, and Solaris. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.

    Adobe recommends users of Adobe Flash Player 10.1.102.64 and earlier versions for Windows, Macintosh, Linux, and Solaris update to Adobe Flash Player 10.2.152.26.
NOTE: since this update was released, Adobe updated Flash Player again to 10.2.152.32. No security bulletin was issued for this update.
  • Adobe - Security Bulletins: APSB11-01 - Security update available for Shockwave Player
    Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.9.615 and earlier
    versions on the Windows and Macintosh operating systems. These vulnerabilities could allow an
    attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected
    system. Adobe recommends users of Adobe Shockwave Player 11.5.9.615 and earlier versions
    update to Adobe Shockwave Player 11.5.9.620 using the instructions provided below.
  • Adobe - Security Bulletins: APSB11-03 - Security updates available for Adobe Reader and Acrobat
    Critical vulnerabilities have been identified in Adobe Reader X (10.0) for Windows and Macintosh; Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX; and Adobe Acrobat X (10.0) and earlier versions for Windows and Macintosh. These vulnerabilities could cause the application to crash and potentially allow an attacker to take control of the affected system.
  • US-CERT Current Activity: Mozilla Releases Updates for Firefox, Thunderbird, and SeaMonkey
    added March 1, 2011 at 02:51 pm | updated March 2, 2011 at 08:01 am

    The Mozilla Foundation has released Firefox 3.6.14 and Firefox 3.5.17 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, conduct cross-site request forgery attacks, cause a denial-of-service condition, or operate with elevated privileges.

    Some of these vulnerabilities also affect Thunderbird and SeaMonkey. The Mozilla Foundation has released Thunderbird 3.1.8 and SeaMonkey 2.0.12 to address these vulnerabilities.

    US-CERT encourages users and administrators to review the Mozilla Foundation security advisories for Firefox 3.6.14 and apply any necessary updates to help mitigate the risks.
  • Foxit Reader Security Bulletins
    Foxit PDF Reader 4.3.1.0218 fixed an unexpected termination of the Foxit Reader software that is caused by illegal accessing memory when opening some special PDF documents.

No comments: