Friday, December 10, 2010

More December Security Patches: QuickTime, Firefox, and a huge Patch Tuesday coming

The second week in December is starting with a bunch of patching.  So far this week, we have QuickTime, Firefox, and Thunderbird with security updates, and next Tuesday promises to be another record Patch Tuesday with patches for IE among other things.  (Updated Fri 10 Dec 2010  18:31 MST)

Apple QuickTime Patch Fixes 15 Flaws — Krebs on Security
Apple this week issued an update that plugs at least 15 security holes in its QuickTime media player.  The patch – which brings QuickTime to version 7.6.9 — quashes several critical bugs that could be exploited to install malicious software were a user to load a poisoned media file. Updates are available for both Mac and Windows versions of the program.

More links:

Mozilla Firefox 3.6.13, Thunderbird 3.1.7

The Mozilla Foundation has released Firefox 3.6.13 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, operate with elevated privileges, spoof the location bar, or operate with elevated privileges.

More links:
Update Fri 10 Dec 2010 18:31 MST:


MS Patch Tuesday heads-up: 17 bulletins, 40 vulnerabilities | ZDNet
The December batch of patches will cover security holes in Microsoft Windows, Office, Internet Explorer, SharePoint and Exchange, according to an advance notice posted Thursday.

Of the 17, Microsoft said two bulletins will be rated “critical,” the company’s highest severity rating.  Of the remainder, 14 will be rated “important.”
More links:


And for a final note, if you use CCleaner, you should update to version 3.01. It has lots of improvements. Get a portable version from the CCleaner - Builds page.

Piriform Blog - CCleaner v3.01
Change log:
  • Improved application startup time and INI loading speeds.
  • Removed need to reboot for Index.dat cleaning.
  • Improved cookie cleaning in Firefox 4.0 Beta 7.
  • Improved Chromium based browser detection and cleaning.
  • Added support for Adobe Reader 10 and Acronis True Image.
  • Improved cleaning for 7-Zip, Adobe Reader 9.0, Microsoft Silverlight Isolated Storage, WinPatrol and Microsoft Management Console.

Security Updates notes for November, 2010

It has been a busy month, and I have not been keeping up with timely posting here.  I will try to keep this a little more current from now on. 

We'll start with November's Patch Tuesday and go forward from there.  The final article linked below is definitely something anyone who uses open WiFi hotspots in Starbucks and other places should read.  Also, if you use Flash Player or Adobe Reader, both have had critical patches in the last month.  If your systems haven't been updated, you need to patch them NOW.  Foxit Reader has also had an update.  IE 6 and 7 have an unpatched flaw which is being exploited "in the wild", so avoid using IE if you possibly can.

November Patch Tuesday: Critical security holes in Microsoft Office | ZDNet
By Ryan Naraine | November 9, 2010, 10:43am PST
Microsoft has shipped a patch for to fix several critical security holes affecting its Office productivity suite and warned that hackers can use RTF (Rich Text Format) e-mails to launch code execution attacks.

The MS10-087 bulletin, which is considered a high-priority update, patches a total of 5 documented vulnerabilities affecting all currently supported Microsoft Office products.

It is rated critical for Office 2007 and Office 2010 because of a preview pane vector in Microsoft Outlook that could trigger the vulnerability when a customer views a specially crafted malicious RTF file, the company explained.
More links:
Mac OS X security flaw publicized after Apple fails to patch | ZDNet
By Ryan Naraine | November 10, 2010, 12:23pm PST
Penetration testing specialists Core Security has publicly released information on a serious security vulnerability in Apple’s Mac OS X and criticized the computer maker for delaying the release of a patch.

The vulnerability, which only affects Apple Mac OS X v10.5, could allow hackers to take complete control of a vulnerable machine via malicious PDF files.

In an advisory, Core Security said Apple claims it already has a patch prepared for this issue but failed to release the fix despite several promises.

Apple did not give any reasons for skipping the patch release.
More links:
Flash Update Plugs 18 Security Holes — Krebs on Security
[ASF: November 4th, 2010]
Adobe on Thursday released an update to its Flash Player software that fixes at least 18 security vulnerabilities, including one that is being exploited in targeted attacks.
More links:

Critical Updates for Adobe Reader, Acrobat — Krebs on Security
[ASF: November 16th, 2010]
Adobe on Tuesday issued a critical update to patch at least two security holes in its PDF Reader and Acrobat software, including one flaw that was publicly disclosed earlier this month.
More links: In a related story: Adobe launches 'sandboxed' Reader X. I am not using Adobe Reader (any version) so I haven't tested it yet. Reviews of the "sandbox" are generally positive but the sandboxing is not complete so I expect it will help but not totally prevent attacks.
By Gregg Keizer, Computerworld - November 18, 2010 02:01 PM ET
Adobe today released Reader X, the next version of its popular software that includes a "sandbox" designed to protect users from PDF attacks.

Reader X on Windows features Protected Mode, a technology that isolates system processes, preventing or at least hindering malware from escaping the application to wreak havoc on the computer.

The new version is also available for Mac OS X and Android, but those editions lack the sandbox.
More links:

Apple patches critical 'drive-by' Safari bugs
By Gregg Keizer, Computerworld - November 18, 2010 02:01 PM ET
Apple today patched 27 vulnerabilities in Safari for Mac OS X and Windows, 85% of them critical bugs that could be exploited to hijack Macs or PCs.


Internet Explorer 0-day Malware Infects Amnesty International Hong Kong Website Visitors | CyberInsecure.com
Visitors to Amnesty International’s Hong Kong website are being bombarded with a host of lethal exploits, including one that attacks an unpatched vulnerability in Microsoft’s Internet Explorer browser, researchers at security firm Websense said.

The injected IE attack code resides directly on the pages of amnesty.org.hk, an indication that the perpetrators were able to penetrate deep into the website’s security defenses. The code exploits a vulnerability disclosed last week that gives attackers complete control over machines running default versions of IE 6 and 7. Version 8 isn’t vulnerable, thanks to security protections built into the browser.


Firesheep Exposes Need For Encryption -- InformationWeek
Using Facebook, Twitter, Yelp, Flickr, or other Web services on an open WiFi network could lead to lead to account hijacking.

An open-source Firefox extension called Firesheep has shined a spotlight on just how insecure it is to use unprotected WiFi networks.

It's widely known that unprotected WiFi networks make sensitive data readily available for anyone with the technical skill necessary to find it ...

Firesheep, which allows anyone to scan unprotected WiFi networks for users who are logged into Facebook, Twitter, Google, Amazon, and a variety of other Web 2.0 services and to impersonate those users by hijacking their session cookie.

"On an open wireless network, cookies are basically shouted through the air, making these attacks extremely easy," wrote Firesheep creator Eric Butler in a blog post. "This is a widely known problem that has been talked about to death, yet very popular Web sites continue to fail at protecting their users. The only effective fix for this problem is full end-to-end encryption, known on the Web as HTTPS or SSL."


Thursday, November 4, 2010

Firefox, Thunderbird patched; Adobe Flash patch due today, other stuff

More patching: Firefox has been patched to plug a 0-day flaw that was being exploited "in the wild", and Mozilla Thunderbird has been patched to fix the same bug (which was not exploitable in TBird).  Adobe's Flash Player and Adobe Reader 9 both have a vulnerability that is also currently being exploited; Adobe is supposed to issue a patch for the Flash player today (November 4, 2010) but Reader won't be patched for another 11 days.  Adobe Reader 8 apparently doesn't have the vulnerability. 

Also, I have been lax about updating this blog, so I have included several older items that have been sitting in my outbox that will affect some of you.  Many vulnerabilities are being found these days in various unusual media players like the Real Player and the Shockwave Player, so if you don't need them I recommend uninstalling them rather than fighting to keep them updated.

Mozilla plugs Firefox drive-by-download zero-day | ZDNet
By Ryan Naraine | October 28, 2010, 10:54am PDT
Mozilla has quickly rushed out a Firefox security patch to provide cover for a zero-day flaw that was being exploited in drive-by malware downloads. ... The patch, rated “critical,” fixes a buffer overflow issue that was under attack at the Nobel Peace Prize web site. ... The vulnerability is fixed in Firefox 3.6.12, Firefox 3.5.15, Thunderbird 3.1.6, Thunderbird 3.0.10 and SeaMonkey 2.0.10.  According to malware hunters tracking the threat, Firefox users who surfed to the Nobel Peace Prize site were silently infected with Belmoo, a Windows Trojan that gives the attacker complete control of the machine.
Adobe under attack: New PDF, Flash zero-day | ZDNet
By Ryan Naraine | October 28, 2010, 12:11pm PDT
Adobe’s security response team is scrambling to respond to new zero-day attacks against a computer hijack vulnerability in two of its most widely deployed products: Flash Player and Adobe PDF Reader.

The flaw, which is currently being exploited in the wild with booby-trapped PDF documents, affects Windows, Mac, Linux and Solaris users. The zero-day attacks are currently targeted Windows users.
Koobface Worm Targets Java on Mac OS X — Krebs on Security
A new version of the infamous Koobface worm designed to attack Mac OS X computers is spreading through Facebook and other social networking sites, security experts warn.

Security software maker Intego says this Mac OS X version of the Koobface worm is being served as part of a multi-platform attack that uses a malicious Java applet to attack users. According to Intego, the applet includes a prompt to install the malicious software:
'Highly critical' flaws hit RealPlayer | ZDNet
By Ryan Naraine | October 18, 2010, 10:54am PDT
Multiple “highly critical” security holes in RealNetworks’ RealPlayer software could expose millions of computer users to remote code execution attacks.

According to an advisory from Secunia, these flaws can be exploited by malicious people to compromise a user’s system.

This RealNetworks security notice details seven different vulnerabilities affecting Windows RealPlayer SP 1.1.4 and and RealPlayer Enterprise 2.1.2.

RealPlayer users are strongly encouraged to apply the available security patches.
Adobe Shockwave Player "Shockwave Settings" Use-After-Free Vulnerability

Juha-Matti reports that an odd Shockwave vulnerability has been identified (http://secunia.com/advisories/42112/.) I call it "odd" because it's not the typical "download crafted flash file and it executes code." The victim has to open the Shockwave settings window while having the malicious website open. It's a new hurdle, but I'm not sure that it's insurmountable.

Zero Day readers, why aren't you patching Flash Player? | ZDNet
Adobe’s plan to rush out a fix for the latest Flash Player zero-day vulnerability got me thinking about patch adoption rates among ZDNet Zero Day readers.

According to our statistics counter, the majority of you (security-savvy readers?) are very tardy in applying Flash Player updates.

New 0-day flaw in IE 6, 7, and 8 not likely to be fixed

This hit the blogs and tech news sites yesterday.  In one of Microsoft's write-ups, they point out that running as a "Limited User" (an account that doesn't have administrator privileges) is one way to avoid this exploit.  Firefox and Chrome are also not subject to this problem.  The Symantec article has the best technical details.

Vulnerability in Internet Explorer Could Allow Remote Code Execution (CVE-2010-3962)

Microsoft has announced a vulnerability in all currently-supported versions of Internet Explorer (6 through 8) that could allow the execution of arbitrary code (advisory 2458511- http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security-advisory-2458511.aspx.) This would likely be leveraged in a drive-by-exploit scenario. They state that DEP (Data Execution Prevention) and Protected Mode are mitigating factors.

Microsoft Warns of Attacks on Zero-Day IE Bug — Krebs on Security
Microsoft Corp. today warned Internet Explorer users that attackers are exploiting a previously unknown security hole in the browser to install malicious software. The company is urging users who haven’t already done so to upgrade to IE8, which includes technology that makes the vulnerability more difficult to exploit.
Microsoft warns of new IE zero-day attacks | ZDNet
Microsoft has raised an alarm for a new round of targeted malware attacks against a zero-day vulnerability in its dominant Internet Explorer browser.

The vulnerability affects all supported versions of Internet Explorer and can be exploited to launch remote code execution (drive by download) attacks, Microsoft said in an advisory.
Microsoft Security Advisory (2458511): Vulnerability in Internet Explorer Could Allow Remote Code Execution
Microsoft is investigating new, public reports of a vulnerability in all supported versions of Internet Explorer. The main impact of the vulnerability is remote code execution. This advisory contains workarounds and mitigations for this issue.

The vulnerability exists due to an invalid flag reference within Internet Explorer. It is possible under certain conditions for the invalid flag reference to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution.

At this time, we are aware of targeted attacks attempting to use this vulnerability. We will continue to monitor the threat environment and update this advisory if this situation changes. On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.
Microsoft Releases Security Advisory 2458511 - The Microsoft Security Response Center (MSRC) - Site Home - TechNet Blogs
Today we released Security Advisory 2458511 to address a new vulnerability that could impact Internet Explorer users if they visit a website hosting malicious code. As of now, the impact of this vulnerability is extremely limited and we are not aware of any affected customers. The exploit code was discovered on a single website which is no longer hosting the malicious code. ... The Security Advisory also details a workaround that customers can apply that will protect all affected versions of IE from this issue. We are working to put have a Microsoft Fix it in place for easy implementation of the workaround. Our Security Research & Defense team has also provided a detailed write up on how the workaround protects against the vulnerability.
New IE Zero-Day used in Targeted Attacks | Symantec Connect
One such case started few days ago when we received information about a possible exploitation using older versions of Internet Explorer as targets. Hackers had sent emails to a select group of individuals within targeted organizations. Within the email, the perpetrators added a link to a specific page hosted on an otherwise legitimate website. The hackers had gotten access to the website account and uploaded content without the owners knowing. Here is what the email looked like:

Thursday, October 21, 2010

Firefox, Thunderbird, Chrome, and Real Player patches released

Time for another round of patching, boys and girls.  Mozilla has patched both Firefox and Thunderbird, and Chrome has some more updates (although Chrome automatically updates itself silently).  If you have the Real Player installed, it, too, needs patching.

SANS: Firefox 3.6.11 and 3.5.14 released Thunderbird 3.1.4 and 3.0.9 released
Firefox 3.6.11 and 3.5.14 released, includes security updates (http://www.mozilla.com/firefox/3.6.11/releasenotes/)
Thunderbird 3.1.4 and 3.0.9 released, includes security patches (http://www.mozillamessaging.com/thunderbird/3.1.5/releasenotes/)
Mozilla releases Firefox 3.6.11 to address 12 flaws - SC Magazine US
Mozilla on Tuesday released an updated version of its Firefox web browser to shore up a dozen vulnerabilities.

Firefox 3.6.11 fixes eight “critical” flaws that could result in a remote attacker installing malicious software on victim machines.
Mozilla Releases Firefox 3.6.11: US-CERT Current Activity
added October 20, 2010 at 08:57 am
The Mozilla Foundation has released Firefox 3.6.11 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, obtain sensitive information, or cause a denial-of-service condition. The Mozilla Foundation has also released Firefox 3.5.14 to address these same vulnerabilities. Some of these vulnerabilities also affect Thunderbird and SeaMonkey and are addressed in Thunderbird 3.1.5 and 3.0.9 and SeaMonkey 2.0.9.

US-CERT encourages users and administrators to review the Mozilla Foundation Security Advisories released on October 19, 2010 and apply any necessary updates to help mitigate the risks.

Firefox dirty dozen: Mozilla patches 'critical' browser flaws | ZDNet
Mozilla has released Firefox 3.6.11 with patches for a dozen security holes, some serious enough to launch attacks if a user simply surfs to a booby-trapped website.

In all, the open-source released nine bulletins documenting 12 security vulnerabilities. Five of the bulletins are rated “critical,” meaning that those vulnerabilities can be exploited to run attacker code and install software, requiring no user interaction beyond normal browsing.

RealNetworks Releases Security Update for RealPlayer Vulnerabilities: US-CERT Current Activity
added October 18, 2010 at 08:08 am
RealNetworks has issued a Security Update to address multiple vulnerabilities affecting RealPlayer. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code.

US-CERT encourages users and administrators to review the RealNetworks security advisory and apply any necessary updates to help mitigate the risks.

Critical RealPlayer Update — Krebs on Security

Real Networks Inc. has released a new version of RealPlayer that fixes at least seven critical vulnerabilities that could be used to compromise host systems remotely if left unpatched.

I’ve never hidden my distaste for this program, mainly due to its history of unnecessarily tracking users, installing oodles of third party software, and serving obnoxious pop-ups. But I realize that many people keep this software installed because a handful of sites still only offer streaming in the RealPlayer format. If you or someone you look after has this program installed, please update it.


Google Releases Chrome 7.0.517.41: US-CERT Current Activity
added October 20, 2010 at 11:47 am
Google has released Chrome 7.0.517.41 for Linux, Mac, and Windows to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, conduct URL spoofing, or bypass security restrictions.

US-CERT encourages users and administrators to review the Google Chrome Releases blog entry and apply any necessary updates to help mitigate the risks.
Google plugs 'high risk' Chrome browser holes | ZDNet

By Ryan Naraine | October 20, 2010, 1:11pm PDT

Google has shipped another Chrome browser update to fix multiple security security vulnerabilities.

Some of these security holes can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and potentially compromise a user’s system, according to this Secunia advisory.  Secunia rates this a “highly critical” update.

Tuesday, October 12, 2010

More discussion of today's patches

It's looking like there really are some PATCH NOW! patches in today's set of fixes for Microsoft Windows.  Also, Oracle released a major patch for the Java Runtime Engine (JRE), taking it to 6u22.  If you have Java installed, you should patch that as well.  Get your Java patch here: Java Downloads for All Operating Systems.  Here are links to two stories with "user-friendly" discussions of why you need to patch:

Patch Tuesday: Critical flaws haunt Microsoft Office, IE browser | ZDNet
Microsoft dropped its largest ever batch of security patches today to cover a record 49 security vulnerabilities, including several browser flaws that could expose Internet Explorer users to drive-by malware downloads.

The Internet Explorer bulletin (MS10-071) fixes a total of 12 vulnerabilities and because of the risk of zero-click drive-by download attacks, Microsoft is urging Windows users to apply this patch immediately.

Windows users should also pay special attention to MS10-076, which covers a serious flaw in the way the operating system handles embedded OpenType (EOT) fonts. This update is rated “critical” for all versions of Windows (including Windows 7 and Windows Server 2008) and can be exploited to launch remote code execution attacks if a computer user simply surfs to a booby trapped Web site.
Microsoft Plugs a Record 49 Security Holes — Krebs on Security
Microsoft today issued 16 update bundles to fix a record-breaking 49 separate security vulnerabilities in computers powered by its Windows operating systems and other software.

“Microsoft has broken several of its own Patch Tuesday records this year, but this month far surpasses them all,” said Joshua Talbot, security intelligence manager, Symantec Security Response. “Perhaps most notable this month is the number of vulnerabilities that facilitate remote code execution. By our count, 35 of the issues fall into this category. These are bugs that could allow an attacker to run any command they wish on vulnerable machines.”

McAfee notes that today’s release exceeds the previous record of 34 vulnerabilities fixed in one go, which was first set in October 2009, and again in June and August of this year.

... Update, 3:58 p.m. ET: Several readers have pointed out that Microsoft took the momentous step today of adding detection for the infamous ZeuS Trojan to its Malicious Software Removal Tool. The MSRT is offered alongside Windows updates and if approved will scan host computers once a month for a variety of the most prevalent threats. It will be interesting to chart the impact of this welcome move by Microsoft.
Java Update Clobbers 29 Security Flaws — Krebs on Security
Oracle today released a critical update to its widely-installed Java software, fixing at least 29 security vulnerabilities in the program.

... Be aware that Java’s updater may by default also include free “extras”
that you may not want, such as the Yahoo! Toolbar or whatever other
moneymaker they decide to bundle with their software this time around,
so be sure to de-select that check box during installation if you don’t
want the add-ons.

Biggest PATCH TUESDAY ever -- some rated PATCH NOW

Today was Microsoft's biggest Patch Tuesday in a long time, possible ever.  SANS (first link below) rates several of these PATCH NOW!, their highest rating.  Anyone who runs as administrator on XP should probably patch ASAP.  I'm patching my work systems and home systems now and will report if I have any problems over the next day or so.

SANS: October 2010 Microsoft Black Tuesday Summary

Microsoft blog about it: Assessing the risk of the October security updates - Security Research & Defense - Site Home - TechNet Blogs