Archive for the ‘ Advisories ’ Category

Mozilla Firefox v3.6.3 released

Mozilla Firefox has been updated to v3.6.3. picture<br /> of firefox logoThis release fixes a critical security issue according to Mozilla Foundation Security Advisory 2010-25:

Title: Re-use of freed object due to scope confusion
Impact: Critical
Announced: April 1, 2010
Reporter: Nils (MWR InfoSecurity)
Products: Firefox

Fixed in: Firefox 3.6.3

Description:

A memory corruption flaw leading to code execution was reported by security researcher Nils of MWR InfoSecurity during the 2010 Pwn2Own contest sponsored by TippingPoint’s Zero Day Initiative. By moving DOM nodes between documents Nils found a case where the moved node incorrectly retained its old scope. If garbage collection could be triggered at the right time then Firefox would later use this freed object.

You can update your version through Firefox’s internal updater by opening Firefox and selecting Help > Check for Updates. You can also get the full download here.

  • Share/Bookmark

Windows Vista SP2 released today

Windows Vista SP2 has been released today and is ready for download. You can grab SP2 from either Windows Update, or from Microsoft’s website here.

What’s new:

•SP2 contains Blue tooth 2.1 feature pack supporting the most recent specification for Blue tooth technology
•Ability to record data on Blu-Ray media,
•Adds Windows Connect Now (WCN) Wi-Fi Configuration to Windows Vista SP2,
•exFAT file system now supports UTC timestamps, which enables correct file synchronization across time zones.
•SP2 provides support for new form factors, such as ICCD/CCID. new form factor support –example USB form factor as opposed to PCMCIA).
•Support for the new VIA 64-bit

CPU Security:

•SP2 includes all previously released security updates, and builds on the proven security benefits of Windows Vista
•Secure Development Lifecycle process updates, where we identify the root cause of each security bulletin and improve our internal tools to eliminate code patterns that could lead to future vulnerabilities
•Reliability
•SP2 addresses previously released reliability updates, as well as addressing crashes, caused by Microsoft code, discovered since the launch of SP1 Performance

•Resume performance when Wi-Fi connection is no longer available after resume from sleep
•Inclusion of Windows Search 4 for improved indexing performance, improved relevancy in search, broader indexing scenario inclusion, as well as new Group Policy integration for Windows Search,
•Improvements to the RSS feeds sidebar gadget to improve update performance and responsiveness.

Application Compatibility:

•It is our goal that applications that run on the Windows Vista Operating System today and are written using public APIs will continue to work as designed on Windows Vista SP2.
•Previously released Application Compatibility updates are included in Windows Vista SP2.
•Spysweeper and ZoneAlarm now working with POP3 email accounts.

Administration and Support Improvements:

•Customers installing .net framework 3.5 service pack 1 will notice shorter download and installation times with Vista service pack 2 or Windows 2008 service pack 2 already installed,
•Service Pack Clean up tool (Compcln.exe): This tool helps restore the hard disk space by permanently deleting the previous versions of the files (RTM & SP1) that are being serviced by Service Pack 2.
•Single installer for both Vista & Server 2008
•Ability to detect an incompatible driver and block service pack installation or warn users of any loss of functionality
•Better error handling and providing more descriptive error messages where possible
•Better manageability through logging in system event log
•Componentization for Serviceability of the installer

Some Specific Fixes/Additions Include:

•Inclusion of Hyper-V
•Event logging support in SPC
•DNS Server now listens over ISATAP address
•Fixes DRM issues from WMP upgrades
•Windows Vista Feature Pack for Wireless
•Reduction of resources required for sidebar gadgets
•Improved power settings for WS08

  • Share/Bookmark

Internet Explorer 8 issues

IE 8 We’ve had a few customers asking about IE 8 and whether they should upgrade or not. While we think IE 8 will be better than it’s predecessors, there appears to be enough issues with it that it would be smart to hold off for a while — at least a month or so until these issues are resolved.

A few of these reported issues are:

  • A zero day security exploit.
  • Issues with Spybot-S&D’s immunization tool and IE-SPYAD , which adds unfavorable sites to your IE’s restricted zone.
  • Some users have reported that after installing IE 8 and applying Windows’ hotfixes, IE 8 has inexplicably reverted back to IE 7 .  Very strange…

Hackers no doubt will also be hammering this browser hard, looking for additional exploits since it’s brand new — another reason to hold off until Microsoft has time to patch these issues.

Know of more issues? Let us know!

  • Share/Bookmark