Vulnerabilities in Symantec pc-Anywhere

Several severe vulnerabilities have recently been identified in Symantec pc-Anywhere. Please see the following link for details.   http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120124_00 Security Advisories Relating to Symantec Products – Symantec pcAnywhere Remote Code Execution, Local Access File Tampering  

Advance notice of January Microsoft patches for Windows OSs and Applications

Microsoft has just sent their advance notice of the patches that are scheduled to be released on Tuesday, January 10.  There are a total of seven patches to be released for January.  All but one of the patches apply to Windows Workstation and Server Operating Systems. The one exception applies to Microsoft Developer Tools and …

Out of Band patch issued for ASP.NET implementations

On Thursday, December 29, Microsoft released an out of band patch to address a vulnerability identified in ASP.NET applications. If exploited, the vulnerability will cause a denial of service event. If you have ASP.NET applications on your webserver, it is recommended that this patch be applied as soon as possible. Please see details at the …

Updates to Firefox, Thunderbird and SeaMonkey released on December 20

On Tuesday, December 20, updates were issued for Firefox, Thunderbird and SeaMonkey to address security vulnerabilities.  For those of you that have customers who use these products, please have them update to version 9.0 (and version 2.6 for SeaMonkey) Currently I don’t see version 9 of Thunderbird available for downloading at this time – I …

Microsoft to start silent upgrades to Internet Explorer in Jan

http://www.computerworld.com/s/article/9222690/Microsoft_gets_silent_upgrade_religion_will_push_IE_auto_updates Microsoft gets silent upgrade religion, will push IE auto-updates Copies Chrome and follows Firefox to get users onto the newest browser without asking permission Beginning in January it will roll out automatic upgrades of IE to the newest version suitable for a user’s version of Windows. Windows XP users still on IE6 or IE7, …

Advance notice of December Microsoft Patches – scheduled for release on Tuesday, December 13

Microsoft has recently provided some details about the patches that are scheduled to be released on Tuesday, December 13. There are fourteen patches scheduled to be released. Depending on Operating System/application up to three patches are classified as CRITICAL and eleven are classified as IMPORTANT. As is generally the case, the older the operating system, …

Vunerabilities identified in Adobe Reader and Acrobat – Not exploitable in version X of these products

As documented at – http://www.adobe.com/support/security/advisories/apsa11-04.html ,  vulnerabilities have been identified in Reader X and Acrobat X. The vulnerabilities are not exploitable due to the sandbox features incorporated in version X.  Versions prior to X are exploitable. Patches for versions prior to X are expected during the week of Dec 12, 2011.  Patches for version X …

Vulnerability in HP LaserJet printers – remote firmware updates possible

Please see the links below for details on a remote firmware update vulnerability that affects HP laserjet printers. Instructions are available to mitigate the exposure. http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449 VULNERABILITY SUMMARY A potential security vulnerability has been identified with certain HP printers and HP digital senders. The vulnerability could be exploited remotely to install unauthorized printer firmware.   …

Updates to Adobe Flash and Air issued on November 11.

A number of security vulnerabilities were addressed in updates for Flash and AIR that were released over the weekend. Please ensure the workstations in your departments/centers are patched as soon as possible. Adobe Flash – version 11.1.102.55 released on November 11 http://www.adobe.com/support/security/bulletins/apsb11-28.html   Adobe Air version 3.1.0.4880 http://www.adobe.com/support/security/bulletins/apsb11-28.html Details Critical vulnerabilities have been identified in …

New version of Java issued for Apple OS-X systems – November 8

A new version of Java was released for Apple OS X on November 8. The current version is 1.6.0_29.  The updates apply to the following OS-X versions. Mac OS-X version 10.7 and later http://support.apple.com/kb/HT5045 Java Update 1 Mac OS-X version 10.6.8 http://support.apple.com/kb/HT5045 Java Update 6