About the security content of QuickTime 7.7.1
QuickTime 7.7.1
- QuickTime
Available for: Windows 7, Vista, XP SP2 or later
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution
Working in Computer Consulting for fun and (sometimes) profit. These are recent security news items everybody who is online should be aware of.
QuickTime 7.7.1
- QuickTime
Available for: Windows 7, Vista, XP SP2 or later
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution
Oracle Corp. released a critical update to plug at least 20 security holes in versions of its ubiquitous Java software. Nearly all of the Java vulnerabilities can be exploited remotely to compromise vulnerable systems with little or no help from users.
If you use Java, take some time to update the program now.
Summary: The patch, which provides a fix for the SSL Beast attack, comes at a time when anti-malware vendors are reporting an “unprecedented wave” of exploits against vulnerabilities in Java.Links to the Java downloads are in yesterday's blog entry Oracle releases BEAST-patched version of Java.
Oracle has shipped a critical Java update to fix at least 20 security vulnerabilities, some serious enough to cause remote code execution attacks.
“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible,” the company warned in an advisory.
According to Oracle, 19 of the 20 vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.
Firefox developers said Tuesday that they have no plans to keep the browser from working with the Java software framework now that Oracle has released a patch that prevents it from being used to decrypt sensitive web traffic.
In a blog post published in late September and updated on Tuesday, Mozilla recommends that Firefox users update their Java plug-in to lower their chances of falling victim to attacks that silently decrypt data protected by the SSL, or secure sockets layer, protocol used by millions of websites. Firefox developers had said previously that they were seriously considering disabling the Java plug-in as a way of preventing the exploit.
Short for Browser Exploit Against SSL/TLS, BEAST was first demonstrated late last month at a security conference in Argentina, where researchers Juliano Rizzo and Thai Duong used the attack to recover an encrypted authentication cookie used to access a PayPal user account in less than two minutes. Oracle has more about the Java update here.
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible. This Critical Patch Update contains 20 new security fixes across Java SE, of which 6 are applicable to JRockit.
Microsoft and Apple today released security updates to fix a slew of critical security problems in their software. Microsoft’s patch batch fixes at least 23 vulnerabilities in Windows and other Microsoft products. Apple’s update addresses more than 75 security flaws in the Windows versions of iTunes.Microsoft Fixes 23 Vulnerabilities Including Critical IE Flaws
Assessing the risk of the October 2011 security updates - Security Research & Defense - Site Home - TechNet BlogsMicrosoft issued its monthly security bulletins today, which include two updates rated as “critical” and which could allow remote code execution. The first, MS11-078, is for a vulnerability in .NET Framework and Microsoft Silverlight. The second critical fix is for MS11-081, a cumulative security update for Internet Explorer. There were six other updates issued that were ranked as “important.”
Microsoft also issued guidance for prioritization of patching. Click on the image below for a full-size chart.
Today we released eight security bulletins. Two have a maximum severity rating of Critical with the other six having a maximum severity rating of Important. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment.Apple slaps another security band-aid on iTunes | ZDNet
Apple has shipped iTunes 10.5 to fix mountains of security problems that expose Windows users to dangerous hacker attacks.US-CERT Current Activity: Apple Releases Multiple Security UpdatesThe security patch, available for Windows 7, Windows Vista and Windows XP SP2, fixes a total of 79 documented vulnerabilities. The most serious of these flaws could allow remote code execution attacks via booby-trapped image or movie files.
added October 12, 2011 at 04:11 pmISC Diary | Apple iTunes 10.5
Apple has released security updates for Apple iOS, Safari 5.1.1, OS X Lion v10.7.2, iWork 09, and Apple TV 4.4 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, and bypass security restrictions.
ISC Diary | Microsoft Black Tuesday Overview October 2011Apple released iTunes 10.5 for Windows and Mac OS X. For those following Apple this comes as no big surprise as there are functionality changes expected due to the imminent release of a new iPhone model. What is however a bit surprising is that they also released an impressive list of fixed vulnerabilities in the windows version of iTunes.
Even more interesting is that that list also mentions that e.g. "For Mac OS X v10.6 systems, this issue is addressed in Security Update 2011-006" or "For OS X Lion systems, this issue is addressed in OS X Lion v10.7.2". And those are respectively a security update and an OS update that are not yet released at the time of writing.
Internet Explorer 9 haunted by 'critical' security vulnerabilities | ZDNetOverview of the October 2011 Microsoft patches and their status.
By Ryan Naraine | October 11, 2011, 12:03pm PDT
Summary: Microsoft
Microsoft’s shiny new Internet Explorer 9 browser contains critical security vulnerabilities that expose users to drive-by download attacks, the company warned today.
fixes drive-by download flaws in the latest version of its dominant
Internet Explorer browser and warns that exploits could emerge within 30
days.
The IE warning highlights this month’s batch of security patches from Microsoft where the company shipped eight security bulletins (two critical, six important) to cover gaping holes in Internet Explorer, .NET Framework & Silverlight, Microsoft Windows, Microsoft Forefront UAG and Microsoft Host Integration Server.follow Ryan Naraine on twitter
According to Microsoft, the IE vulnerabilities could be exploited if a user simply surfs to a maliciously rigged website.The IE update (MS11-081),
available for all users or Microsoft Windows and all versions of
Internet Explorer, covers at least eight documented security holes in
the world’s most widely used browser.The most severe vulnerabilities could
allow remote code execution if a user views a specially crafted Web page
using Internet Explorer. An attacker who successfully exploited any of
these vulnerabilities could gain the same user rights as the local user.
Users whose accounts are configured to have fewer user rights on the
system could be less impacted than users who operate with administrative
user rights.
"99.8 per cent of all virus/malware infections caused by commercial exploit kits are a direct result of the lack of updating five specific software packages"
Adobe Flash Player v 17.0.0.169 (IE) 17.0.0.169 (Firefox) (updated 14 Apr 2015). NOTE: update BOTH IE and Firefox Flash Players.Home and business users can scan their systems using the Secunia Personal Software Inspector.
Adobe Reader (and Acrobat) v10.1.13 or v11.0.10 (updated 9 Dec 2014). NOTE: AR 9 is no longer being updated. Switch or update!
Adobe - Acrobat : For Windows
Java Runtime Engine (JRE) 8.0.45 (8u45) (updated 14 Apr 2015)
Apple Quicktime v7.7.6 (updated 22 Oct 2014)
WARNING: Adobe (Flash, Reader) and Oracle (Java) OFTEN install additional software like toolbars or Google Chrome from their download pages. UNCHECK this additional software unless you really want it.
- WinPatrol
Now at v33.5.2015.3
last update: 14 Apr 2015- Spybot Search and Destroy
Now at v2.4
last update: 22 Apr 2015- SpywareBlaster
Now at v5.0
last update: 30 Mar 2015