Tuesday, May 15, 2012

Apple OS X security update for version 10.5 (Leopard)

Apple has released a security update for an older version of OS X, version 10.5 AKA Leopard, which is a "must install" for users with that version.  If you are running Leopard* you should update IMMEDIATELY.

Note that while Apple claims to disable "old versions of Flash" in their current update set, this is not completely true. They do NOT check to see if you are running the latest version, version 11.2.202.235. They only disable Flash you if you are running version 10.1.102.64 or older, but there are many versions of Flash between 10.1.x and the current 11.2.x version. This is NOT a complete fix IMHO. If you are running Leopard, please apply this security update from Apple AND update your Flash Player manually from Adobe's website.

About the security content of Leopard Security Update 2012-003
Available for: Mac OS X v10.5 to 10.5.8 Intel

Impact: Out-of-date versions of Adobe Flash Player are disabled

Description: This update disables Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory. This update presents the option to install an updated version of Flash Player from the Adobe website.

Apple releases Leopard update, Flashback removal tool | TUAW - The Unofficial Apple Weblog
Apple has released a security update for Leopard, the first in quite a while, as well as a Flashback removal tool for that version of the OS.

According to Apple, Leopard Security Update 2012-003 "disables versions of Adobe Flash Player that do not include the latest security updates and provides the option to get the current version from Adobe's website."

Also, the Flashback Removal Security Update "removes the most common variants of the Flashback malware. If the Flashback malware is found, a dialog will notify you that malware was removed. In some cases, the update may need to restart your computer in order to completely remove the Flashback malware."

Grab them both to secure your Leopard machine.


* To determine what version of OS X you are running, follow the instructions on this page: How do I find my operating system (OS) version?

Monday, May 14, 2012

Adobe to patch Illustrator, Photoshop, and Flash Pro CS5.x for free

A few days ago I blogged about Adobe Security Patches for May 8, 2012
"Adobe has only fixed the security holes in new versions, and you have to pay to upgrade."
Well, Adobe realized it had some egg on its face regarding this policy and has quickly changed its mind. It will be providing security patches at some unspecified date in the future.

Adobe about-face: Photoshop, Illustrator patches will be free | ZDNet
Facing widespread criticism for its decision to bundle critical security updates into paid upgrades for Photoshop and Illustrator, Adobe has changed course and will now backport the fixes to existing software versions.

The company’s about-face was included in an update to the security bulletin:

We are in the process of resolving the vulnerabilities addressed in these Security Bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x (12.x) and Adobe Flash Professional CS5.x, and will update the respective Security Bulletins once the patches are available.

The company did not provide a timeline for when the backported patches will be available.

Adobe backs down, will patch old software for free
Faced with a backlash from angry customers, Adobe bowed to the pressure and backpedalled on its original decision, deciding to patch the eight vulnerabilities in question free of charge.

"We are in the process of resolving the vulnerabilities addressed in these security bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x and Adobe Flash Professional CS5.x, and will update the respective security bulletins once the patches are available," they stated.

They did not say how long it will take for the patches to be issued.

Tuesday, May 8, 2012

Adobe Security Patches for May 8, 2012

Adobe has released two security bulletins for Adobe Photoshop CS and Adobe Flash Professional CS.  However, there is bad news for those who use these Adobe products to create content,  Adobe has only fixed the security holes in new versions, and you have to pay to upgrade.  The latest Adobe Security bulletins and advisories as of May 8, 2012, links to the advisories for these products which tells users who cannot upgrade that "Adobe recommends users follow security best practices and exercise caution when opening files from unknown or untrusted sources."  In other words, you're being abandoned. 

Those who cannot upgrade (or who choose not to support Adobe any longer) should look into alternative products such as GimpShop or LibreOffice Impress.  Two articles listing alternatives to these Adobe programs are here:
EDIT Fri 11 May 2012 14:32: Other blogs are chiming in on this issue, and they're NOT happy about Adobe's position:

In other Adobe security news, today Adobe has released another patch, this one free, for the Shockwave Player.  Details here: Security update available for Adobe Shockwave Player.

Adobe - Security Bulletins: APSB12-11 Security bulletin for Adobe Photoshop

Summary

Adobe released a security upgrade for Adobe Photoshop CS5.5 and earlier for Windows and Macintosh. This upgrade addresses vulnerabilities that could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system.

Adobe has released Adobe Photoshop CS6, which addresses these vulnerabilities. For users who cannot upgrade to Adobe Photoshop CS6, Adobe recommends users follow security best practices and exercise caution when opening files from unknown or untrusted sources.

Affected software versions

Adobe Photoshop CS5.5 and earlier versions for Windows and Macintosh

Solution

Adobe has released Adobe Photoshop CS6 (paid upgrade), which addresses these vulnerabilities. For users who cannot upgrade to Adobe Photoshop CS6, Adobe recommends users follow security best practices and exercise caution when opening files from unknown or untrusted sources.

Adobe - Security Bulletins: APSB12-12 Security bulletin for Adobe Flash Professional

Summary

Adobe released a security upgrade for Adobe Flash Professional CS5.5 (11.5.1.349) and earlier for Windows and Macintosh. This upgrade addresses a vulnerability that could allow an attacker who successfully exploits this vulnerability to take control of the affected system.

Adobe has released Adobe Flash Professional CS6, which addresses this vulnerability. For users who cannot upgrade to Adobe Flash Professional CS6, Adobe recommends users follow security best practices and exercise caution when opening files from unknown or untrusted sources.

Affected software versions

Adobe Flash Professional CS5.5 (11.5.1.349) and earlier for Windows and Macintosh

Solution

Adobe has released Adobe Flash Professional CS6 (paid upgrade), which addresses this vulnerability. For users who cannot upgrade to Adobe Flash Professional CS6, Adobe recommends users follow security best practices and exercise caution when opening files from unknown or untrusted sources.

Apple updates iOS for iPx devices

Information about the content of this update is not currently available, as Apple is usually VERY close-mouthed about security fixes, but all the sites are saying there are security holes that are plugged. Apple's security write-up on this update (HT5278) is still coming up blank.   The best write-up I have seen is the ZDNet article linked near the end of this blog posting.

Given the latest spate of fixes to other Apple operating systems, I would recommend that if you are offered this update through iTunes you accept it and update.  Of course, you are going to back up your data before you update, right?

ISC Diary | iOS 5.1.1 Software Update for iPod, iPhone, iPad
Apple released iOS 5.1.1 for iPod, iPhone, iPad (exclude Mac OS X) only available through iTunes. The updates address Safari and WebKit for iPhone 3GS, iPhone 4, iPhone 4S, iPod touch (3rd generation) and later, iPad, iPad 2. At the time of this writing, the advisory was still not posted (APPLE-SA-2012-05-07-1) but the update is available through iTunes.
Apple offers iOS 5.1.1 update, fixes some serious vulnerabilities | Naked Security
Apple's latest update to iOS just came out. Version 5.1.1 is more than just a cosmetic fix: it patches at least three security flaws, all of which should be considered serious.

Information about the update can be found in Apple's knowledgebase article DL1521.

Unfortunately, the security reasons for updating sooner rather than later are hard to find from DL1521.

The page leads with a list of five "improvements and bug fixes", none of which is a compelling reason on its own to update now.

As usual, Apple relegates the security content of the update to the well-known landing page HT1222. But when I visited, the most recent security updates in the list were still April's malware-related Flashback fixes.

Nevertheless, the page you need to consult for iOS 5.1.1 does exist - it's HT5278, and if you have an iDevice, I strongly suggest you read it.

Apple patches serious security holes in iOS devices | ZDNet
Apple has shipped a high-priority iOS update to fix multiple security holes affecting the browser used on iPhones, iPads and iPod Touch devices.

The iOS 5.1.1 update fixes four separate vulnerabilities, including one that could be used to take complete control of an affected device.

Here’s the skinny of this batch of updates:
  • A URL spoofing issue existed in Safari. This could be used in a malicious web site to direct the user to a spoofed site that visually appeared to be a legitimate domain. This issue is addressed through improved URL handling. This issue does not affect OS X systems.
  • Multiple security holes in the open-source WebKit rendering engine.  These could lead to cross-site scripting attacks from maliciously crafted web sites. These vulnerabilities were used during Google’s Pwnium contest at this year’s CanSecWest conference.
  • A memory corruption issue in WebKit. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.  This issue was discovered and reported by Google’s security team.

This patch is only available via iTunes. To check that the iPhone, iPod touch, or iPad has been updated:

  • Navigate to Settings
  • Select General
  • Select About. The version after applying this update will be “5.1.1″.

Friday, May 4, 2012

Extremely Urgent: Adobe Flash Player Emergency Patch Released

Update your Adobe Flash Players ASAP, especially if you run Windows and
use Internet Explorer or any of Microsoft's email programs (which use IE
to display email).  The vulnerability exists in all versions of the
Flash Player, but has not been used on other platforms -- YET.  Lots of noise about this in the press.

Adobe - Security Bulletins: APSB12-09 - Security update available for Adobe Flash Player
Release date: May 4, 2012
Adobe warns: Flash Player malware hitting IE on Windows users | ZDNet
By Ryan Naraine | May 4, 2012, 8:24am PDT

Summary: Although the vulnerability affects Flash Player on all platforms, the malware attacks target Flash Player on Internet Explorer for Windows only.

Adobe has shipped an extremely urgent Flash Player patch to block in-the-wild malware attacks against Windows users.

Adobe described the attacks as “targeted” and warned that malicious Flash files are being delivered in e-mail messages.

Although the vulnerability affects Flash Player on all platforms, the malware attacks target Flash Player on Internet Explorer for Windows only.
Adobe Releases Security Advisory for Adobe Flash Player - US-CERT Current Activity
Friday, May 4, 2012 at 11:06 am

Adobe has released a Security Advisory for Adobe Flash Player to address a vulnerability affecting the following software versions:

  • Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh, and Linux operating systems
  • Adobe Flash Player 11.1.115.7 and earlier versions for Android 4.x
  • Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and 2.x

This vulnerability may allow an attacker to cause a denial-of-service condition or take control of the affected system.
Critical Flash Update Fixes Zero-day Flaw — Krebs on Security
Adobe Systems Inc. today issued a security update to its Flash Player software. The company stressed that the update fixes a critical vulnerability that malicious actors have been using in targeted attacks.

Adobe classifies a security flaw as critical if it can be used to break into vulnerable machines without any help from users. The company said the vulnerability (CVE-2012-0779) fixed in the version released today has been exploited in targeted attacks designed to trick the user into clicking on a malicious file delivered in an email message, and that the exploit used in the attacks seen so far target Flash Player on Internet Explorer for Windows only.

Tuesday, April 17, 2012

Mac Users need to update Java AGAIN

If you're running an Apple Mac with OS X 10.6 or later, you need to make sure your software is up-to-date, as Apple has updated Java again.  Sorry, OS X 10.5 and earlier users, you're out of luck, and it doesn't look like Apple is ever going to patch these older versions.  Users of older Macs should uninstall or disable Java ASAP as there is an unpatched vulnerability that makes you subject to drive-by infection.

AFAICT Apple has abandoned users of Tiger and Leopard (v10.5).  Apple expects users to pay to upgrade at least to OS X 10.6 (Snow Leopard) or 10.7 (Lion).  If your computer won't run one of those, too bad, so sad, please give Apple more money for a newer Mac (or switch to Linux, which is free).  BUT see the last item below for more info on what you can do if you're using an old Mac.

Third Apple Java update rids infections and turns off Java - SC Magazine
Apple has released a third Java update related to the outbreak Flashback, but this time, the patch comes with a detection and removal capability for the prolific trojan.
ISC Diary | Flashback Trojan Removal Tool Released
Published: 2012-04-14
Earlier in the week Apple released a Java update which included software to remove the Flashback Trojan from OS X Lion machines running Java.

The Flashback Trojan removal tool is now also available for OS X Lion machines not running Java. This Flashback malware removal tool is available through the OS X Software Update tool, or from Apple's downloads site at http://www.apple.com/support/downloads/.
About the security content of Java for OS X 2012-003 and Java for Mac OS X 10.6 Update 8
This document describes the security content of Java for OS X 2012-003 and Java for Mac OS X 10.6 Update 8, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.
About the security content of Flashback malware removal tool
Available for: OS X v10.7 or later without Java installed


I just came across this interesting note -- and if I were a home user, I would certainly be using OpenDNS instead of Comcast's DNS or Qwest's DNS:

OpenDNS´s Allison Rhodes reports that OpenDNS ... is blocking the Flashback Trojan. People not yet using OpenDNS need only to set up the service on their wireless router, computer or device to secure their computers and devices from the attack.

... Even for those people who find their machine has already been infected by Flashback, Rhodes maintains, enabling OpenDNS will prevent the malware from connecting to its command and control and causing your machine any damage.

To set up the OpenDNS free service, you need simply create an account, choose your router or computer and follow the step-by-step instructions. Note that setting up OpenDNS on your router will protect all devices connecting to the Internet through your WiFi network, and Windows users should use OpenDNS, too.

For more information, visit http://blog.opendns.com/

Seen here: Free mini-apps to check your Mac for Flashback malware infection AppleTell.

Thursday, April 12, 2012

Patch Tuesday April 2012 - Critical updates for Windows, Office and Adobe Reader

I'm not seeing any negative feedback on the Patch Tuesday updates from this month, so go ahead and update.  Updates apply to both Microsoft Windows/Office and Adobe Reader/Acrobat 9/5 and 10.x.  ISC/SANS have rated most of the Microsoft patches as "Critical", which means they are either being exploited on a targeted basis or exploits are imminent.  The Bad Guys *_will_* be taking advantage of unpatched machines in the next few weeks.  The Krebs-on-Security entry below has the most user-friendly and descriptive write-up.  Links to the official Microsoft and Adobe security bulletins are below for the nerds among you.

Microsoft warns of 'limited, targeted attacks' against Windows vulnerability | ZDNet

By | April 10, 2012, 11:52am PDT

Summary: The vulnerability under attack exists in Windows Common Controls and can be exploited to launch remote code execution attacks if a user simply surfs to a malicious website.

Microsoft today shipped patches for at least 11 documented security vulnerabilities, including one that’s already being hit with “limited, targeted attacks.”

The vulnerability under attack — now fixed today with the MS12-027 bulletin — exists in Windows Common Controls and can be exploited to launch remote code execution attacks if a user simply surfs to a malicious website.

The vulnerability is caused when the MSCOMCTL.OCX ActiveX control, while being used in Internet Explorer, corrupts the system state in such a way as to allow an attacker to execute arbitrary code.

Microsoft is calling on Windows users to apply this bulletin as a priority because of the high-risk of code execution attacks.
Patch Tuesday April 2012 – Critical updates for Windows, Office and Adobe Reader | Naked Security
This month Microsoft has released six patches, four critical, for eleven vulnerabilities in Office, Windows and various server products. ...

Adobe, not wanting to feel left out, also delivered fixes for four vulnerabilities in Adobe Reader and Acrobat versions 9 and X.

All four vulnerabilities can lead to remote code execution, so I advise everyone be sure to update to Reader/Acrobat 10.1.3.

Adobe, Microsoft Issue Critical Updates — Krebs on Security
Adobe and Microsoft today each issued critical updates to plug security holes in their products. The patch batch from Microsoft fixes at least 11 flaws in Windows and Windows software. Adobe’s update tackles four vulnerabilities that are present in current versions of Adobe Acrobat and Reader.

Seven of the 11 bugs Microsoft fixed with today’s release earned its most serious “critical” rating, which Microsoft assigns to flaws that it believes attackers or malware could leverage to break into systems without any help from users. In its security bulletin summary for April 2012, Microsoft says it expects miscreants to quickly develop reliable exploits capable of leveraging at least four of the vulnerabilities.

Among those is an interesting weakness (MS12-024) in the way that Windows handles signed portable executable (PE) files. According to Symantec, this flaw is interesting because it lets attackers modify signed PE files undetected.

“In addition, the attacker doesn’t need to worry about controlling memory; once the user runs the content, the device has been infected,” wrote John Harrison, group product manager for Symantec Security Response. “The most common attack will probably be a scenario in which a site offers a free download of a specific program that appears to be legitimately signed.”

Wolfgang Kandek, chief technology officer for vulnerability management firm Qualys, is particularly worried about MS12-027, because the weakness spans an unusually wide range of Microsoft products. Microsoft agrees, calling this patch the highest priority security update this month.

“What makes this bulletin stand out is that Microsoft is aware of attacks in the wild against it and it affects an unsually wide-range of Microsoft products, including Office 2003 through 2010 on Windows, SQL Server 2000 through 2008 R2, BizTalk Server 2002, Commerce Server 2002 through 2009 R2, Visual FoxPro 8 and Visual Basic 6 Runtime,” Kandek said. “Attackers have been embedding the exploit for the underlying vulnerability (CVE-2012-0158) into an RTF document and enticing the target into opening the file, most commonly by attaching it to an e-mail. Another possible vector is through web browsing, but the component can potentially be attacked through any of the mentioned applications.”

ISC Diary | Microsoft April 2012 Black Tuesday Update - Overview
Published: 2012-04-10,
Last Updated: 2012-04-11 01:57:49 UTC
by Swa Frantzen (Version: 1)
Overview of the April 2012 Microsoft patches and their status.
Adobe warns of Reader X security holes | ZDNet

By | April 11, 2012, 11:26am PDT

Summary: Adobe ships patches for flaws that could cause the application to crash and potentially allow an attacker to take control of the affected system.

Adobe’s flagship PDF Reader/Acrobat software contains multiple security vulnerabilities that expose computer users to dangerous hacker attacks.

Adobe warned about the vulnerabilities in a security bulletin that contained patches for Windows, Mac OS X and Linux users.


Microsoft Security Bulletin Summary for March 2012
Adobe - Security Bulletins: APSB12-08 - Security updates available for Adobe Reader and Acrobat