Wednesday, June 23, 2010

Mozilla Releases Firefox 3.6.4

It seems to be a little faster than 3.6.3 ... and it includes some better crash protection. Go get it!

Mozilla Releases Firefox 3.6.4
The Mozilla Foundation has released Firefox 3.6.4 and Firefox 3.5.10 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, or conduct cross-site scripting attacks. Some of these vulnerabilities also affect Thunderbird and SeaMonkey.

US-CERT encourages users and administrators to review the Security Advisories for Firefox 3.6 and Firefox 3.5 and apply any necessary updates to help mitigate the risks.
Update Thu 24 Jun 2010 09:46: Mozilla patches 9 Firefox bugs, adds plug-in crash protection | Security Central - InfoWorld
Mozilla on Tuesday patched nine vulnerabilities, six of them critical, in Firefox 3.6 and Firefox 3.5.

But rather than highlighting the security fixes in Firefox 3.6.4, the company instead emphasized the addition of crash protection, a move meant to keep the browser alive when popular plug-ins drop dead.

Even legitimate support sites can go bad ....

Just one more reason to browse the Internet using Firefox with NoScript and as a non-administrator.  Use a limited account or use DropMyRights when you browse from machines where you must run as administrator.

Lenovo Support Website Loads Malicious IFrame, Infects Visitors With Trojan | CyberInsecure.com
The support site of leading Chinese PC manufacturer Lenovo has been compromised by unknown attackers who injected a rogue IFrame into the pages over the weekend. Security researchers warn that unwary visitors looking for drivers are exposed to several exploits that install the Bredolab trojan onto their computers.

According to a report from Vietnamese antivirus vendor Bkis, the pages have been infected since at least Sunday afternoon. However, some users have been reporting getting antivirus warnings when visiting Lenovo’s download website since Saturday.

The IFrame points to an exploit kit hosted on a domain called volgo-marun.cn. After performing several checks to determine what vulnerable software they had installed on their computer, the visitors were served with exploits targeting older versions of Internet Explorer, Adobe Reader or Adobe Flash player.

“These exploit codes attempt to load file hxxp://volgo-marun.cn/pek/exe.exe which is a virus, onto victim’s computer. The virus is a new variant of Bredolab Botnet […]. After being loaded onto the computers, the virus copies itself as %Programs%\Startup\monskc32.exe and receives commands from C&C server with domain sicha-linna8.com,” Le Minh Hung, senior security researcher at Bkis, writes.

At the moment, the malicious executable is detected by only ten of the 41 antivirus products listed on VirusTotal. The entire download.lenovo.com subdomain has been blacklisted by Google’s Safe Browsing service. This means that Firefox or Chrome users should see malware warnings when opening resources hosted on it.

“Of the 46 pages we tested on the site over the past 90 days, 39 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-06-20, and the last time suspicious content was found on this site was on 2010-06-20. Malicious software includes 1 trojan(s). Malicious software is hosted on 1 domain(s), including volgo-marun.cn/,” a detailed explanation of the Google warnings reads.

Even though the malicious .cn domain appears to be dead at the moment, it could return back online at any time. Therefore, users are advised to stay clear of the Lenovo support website for a couple of days, until the manufacturer has a chance to clean it up and plug the hole that allowed the compromise in the first place.

Thursday, June 17, 2010

Apple iTunes 9.2 released

WebKit security flaws haunt Apple's iTunes | ZDNet
Apple has shipped a critical security patch for its iTunes media player to fix several gaping security holes that expose Windows users to hacker attacks.

The vulnerabilities could be exploited to launch remote code execution attacks if a user simply opens an image file or surfs to a rigged Web site. The update applies to Windows 7, Windows Vista and Windows XP machines.

In all, the new iTunes 9.2 fixes 40 documented vulnerabilities, most affecting the WebKit rendering engine. The WebKit vulnerabilities are the same that affected Apple’s Safari browser.
US-CERT Current Activity: Apple Releases iTunes 9.2
       added June 17, 2010 at 08:19 am
Apple has released iTunes 9.2 for Windows systems to address multiple vulnerabilities affecting the ColorSync, ImageIO, and WebKit packages. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users and administrators to review Apple article HT4220 and apply any necessary updates to help mitigate the risks.

Wednesday, June 16, 2010

Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player

Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player - Adobe Product Security Incident Response Team (PSIRT)
Earlier today, Apple released security update 2010-004 / Mac OS X v10.6.4. This update includes an earlier version of Adobe Flash Player (version 10.0.45.2) than available from Adobe.com. While the Mac OS X v10.6.4 update does not appear to downgrade users who have already upgraded to Adobe Flash Player 10.1, Adobe recommends users verify they are using the latest, most secure version of Flash Player (10.1.53.64) available for download from http://www.adobe.com/go/getflashplayer.

To verify the Adobe Flash Player version number installed on your system (after applying the Mac OS X security update), access the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.

OS X Patch Tuesday: 28 fixes

Apple releases advisory for Mac OS X - Multiple vulnerabilities discovered
Apple released today an advisory for multiple vulnerabilities discovered in Mac OS X. Impacted programs includes CUPS, Desktop Services, Folder Manager, Help Viewer, iChat, ImageIO, Kerberos, libcurl, Network Autorization, Open Directory, Printer Setup, Printing, Ruby, SMB File Server, Squirrelmail, and Wiki Server. Mac users: please download the Mac OS X Server v10.6.4 Update Mac mini (Mid 2010) at http://support.apple.com/downloads/DL1055/en_US/MacOSXSrvUp10.6.4MacminiMid2010.dmg. Better to patch quickly before an exploit goes outside the wild.

More information for the advisory at http://support.apple.com/kb/HT4188.
Apple plugs 28 Mac OS X security holes | ZDNet
Apple has shipped another mega Mac OS X patch bundle to fix a total of 28 documented security vulnerabilities affecting the Mac ecosystem.

The update, which includes fixes for the Adobe Flash Player plugin and several open-source components, is rated highly-critical because it exposes Mac OS X users to remote code execution attacks.

In some cases, a hacker could take complete control of an affected machine if a user is lured to a malicious Web site or views a rigged movie file.

Here’s the skinny on the most serious issues fixes in this Security Update 2010-004 / Mac OS X v10.6.4 bundle:

Windows XP Help vulnerability now "in the wild"

There are multiple reports of drive-by downloads appearing. Drive-by downloads are dangerous because you can be infected without taking any action other than browsing to a webpage which carries the infection. If you are running Windows XP as an administrator, you should probably immediately apply one of the workarounds described on the Microsoft page linked below.

Microsoft confirms exploits targeting Ormandy 0-day - SC Magazine US
Five days after a Google researcher published details of a zero-day vulnerability affecting the Windows Help and Support Center, in-the-wild exploits have emerged, Microsoft said Tuesday.

The software giant said it was aware of "limited exploits" affecting XP users, according to a tweet posted by the Microsoft Security Response Center. Server 2003 also is vulnerable to the bug, but Microsoft said it has not received any attack samples targeting those customers.

As affected users await a permanent fix, they are encouraged to apply a "Fix It" workaround, as outlined in a security advisory released Thursday by Microsoft.
Windows XP zero-day under attack; Use Microsoft's "fix-it" workaround | ZDNet
Just five days after Google researcher Tavis Ormandy released details of a critical vulnerability affecting Windows XP and Windows Server 2003, malware authors have struck, exploiting the flaw to plant malware on Windows machines.

The attacks, described by Microsoft as “limited,” are being distributed on rigged Web sites (drive-by downloads).

Official Microsoft bulletin here:
Microsoft Security Advisory (2219475): Vulnerability in Windows Help and Support Center Could Allow Remote Code Execution

Home users should immediately run the Microsoft "Fixit" from this page: Vulnerability in Help Center could allow remote code execution. They should also download the "Disable" version of the "FixIt" for use later, as Microsoft often makes the FixIt page disappear when the problem is fixed permanently, removing access to the "UnFixit" for those who haven't planned ahead.

Thursday, June 10, 2010

Adobe patches Flash, but Adobe Reader 9 remains unpatched

A nasty hole in Adobe Flash (all platforms: Windows, Mac, Linux) has been patched on the Windows version. A related hole in Adobe Reader 9 is still unpatched. I have patched my Adobe Flash players and am in the process of patching Flash on business client computers. For home users, links to the Flash patches can be found here: Adobe - Security Bulletins: APSB10-14 Security update available for Adobe Flash Player -- but network admins and those not wishing to use Adobe's magical "Download Mangler" should read to the end of this blog entry to find links to Flash patches they can distribute more easily.

To protect yourself if you run Adobe Reader 9, note that the vulnerability relates to Flash objects embedded inside PDF documents. Adobe Reader 8 (and earlier versions) can't play embedded flash objects and so is not vulnerable. To protect AR9, just rename authplay.dll, which according to Adobe: "(t)he authplay.dll that ships with Adobe Reader 9.x and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat." See Security Advisory for Flash Player, Adobe Reader and Acrobat (APSA10-01) for more information.

Consumer-friendly write-ups and notifications can be found on the following pages:

Adobe Flash Update Plugs 32 Security Holes — Krebs on Security
As promised, Adobe has released a new version of its Flash Player software to fix a critical security flaw that hackers have been exploiting to break into vulnerable systems. The update also corrects at least 31 other security vulnerabilities in the widely used media player software.

The latest version, v. 10.1, fixes a number of critical flaws in Adobe Flash Player version 10.0.45.2 and earlier. Don’t know what version of Flash you’ve got installed? Visit this page to find out. The new Flash version is available for Windows, Mac and Linux operating systems, and can be downloaded from this link.

Note that if you use both Internet Explorer and non-IE browsers, you’re going to need to apply this update twice, once by visiting the Flash Player installation page with IE and then again with Firefox, Opera, or whatever other browser you use.
Adobe plugs 32 security holes in 'critical' Flash Player patch | ZDNet
Adobe has shipped a “critical” Flash Player update to fix a total of 32 documented vulnerabilities in the ubiquitous software product.

The Adobe Flash Player 10.1.53.64 update comes on the heels of last week’s in-the-wild attacks against a zero-day hole in Adobe’s Reader and Flash Player product. This patch fixes that vulnerability along with 31 other serious security problems.
US-CERT Current Activity: Adobe Releases Flash 10.1
added June 10, 2010 at 08:00 pm

Adobe has released a Security Bulletin to address vulnerabilities in Adobe Flash Player 10.0.45.2 and earlier versions and in Adobe AIR 1.5.3.9130 and earlier versions. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users and administrators to review Adobe Security Bulletin APSB10-14 and to update to Adobe Flash Player 10.1 to help mitigate the risks.
Here are links to download the Flash patches directly, without going through Adobe's pages:Once you download these Flash patches, they can be installed without any further clicking by running them with the "/install" command-line switch.