Translate

Posts mit dem Label Security Update werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Security Update werden angezeigt. Alle Posts anzeigen

4/16/2014

UPDATES: Massive (Java) Oracle Critical Patch Update Advisory - April 2014

 

Description

A Critical Patch Update (CPU) is a collection of patches for multiple security vulnerabilities. Critical Patch Update patches are usually cumulative, but each advisory describes only the security fixes added since the previous Critical Patch Update advisory. Thus, prior Critical Patch Update advisories should be reviewed for information regarding earlier published security fixes. Please refer to:
Critical Patch Updates and Security Alerts for information about Oracle Security Advisories.
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible. This Critical Patch Update contains 104 new security fixes across the product families listed below.

Please note that a blog entry summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at https://blogs.oracle.com/security.
This Critical Patch Update advisory is also available in an XML format that conforms to the Common Vulnerability Reporting Format (CVRF) version 1.1. More information about Oracle's use of CVRF is available at: http://www.oracle.com/technetwork/topics/security/cpufaq-098434.html#CVRF.

Affected Products and Components

Security vulnerabilities addressed by this Critical Patch Update affect the products listed in the categories below.  The product area of the patches for the listed versions is shown in the Patch Availability column corresponding to the specified Products and Versions column.   Please click on the link in the Patch Availability column below or in the Patch Availability Table to access the documentation for those patches.

For further Information, go to:

The ingredients are:
2 for Oracle Database Server
20 for Oracle Fusion Middleware
  3 for Oracle Hyperion
10 for Oracle Supply Chain Products Suite
  8 for Oracle PeopleSoft Products
  1 for Oracle Siebel CRM
  1 for Oracle iLearning
37 for Oracle Java SE
  3 for Oracle and Sun Systems Products Suite
  5 for Oracle Virtualization
14 for Oracle MySQL

1/28/2014

SECURITY UPDATE: Google Releases Google Chrome Update 32.0.1700.102

Google has released Google Chrome 32.0.1700.102 for Windows, Mac, Linux and Chrome Frame to address multiple vulnerabilities. These vulnerabilities could allow a remote attacker to cause a denial of service or bypass intended security restrictions. Follow the Link for Update:


Stable Channel Update

Chrome has been updated to 32.0.1700.102 for Windows, Mac, Linux and Chrome Frame.

This update has fixes for the following issues:
  • Mouse Pointer disappears after exiting full-screen mode. (317496)
  • Drag and drop files into Chrome may not work properly. (332579) 
  • Quicktime Plugin crashes in Chrome. (308466)
  • Chrome becomes unresponsive. (335248)
  • Trackpad users may not be able to scroll horizontally. (332797) 
  • Scrolling does not work in combo box. (334454)
  • Chrome does not work with all CSS minifiers such as whitespace around a media query's `and` keyword. (333035)
Security Fixes and Rewards
This update includes 14 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.

[$1000][330420] High CVE-2013-6649: Use-after-free in SVG images. Credit to Atte Kettunen of OUSPG.
[$3000][331444] High CVE-2013-6650: Memory corruption in V8. This issue was fixed in v8 version 3.22.24.16. Credit to Christian Holler.

We would also like to thank cloudfuzzer and miaubiz for working with us during the development cycle to prevent security bugs from ever reaching the stable channel. $6000 in additional rewards were issued.

Many of the above bugs were detected using AddressSanitizer.

A partial list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.

1/25/2014

Apple Releases iTunes 11.1.4

Apple has released a security update for Apple iTunes 11.1.4 to address multiple vulnerabilities. These vulnerabilities could allow an attacker to execute arbitrary code or cause a denial-of-service condition.

For Details See:  http://support.apple.com/kb/HT6001



12/02/2013

Security Issues: Critical Update on D-Link Routers

The Taiwanese D-Link Corporation has released several Critical Security Updates for some of its earlier Internet Routers. These Patches are closing some backdoors in the devices that could let attackers catch remote access over unpatched ones.



As D-Link informs on their Security-Support-Page:

"Various media reports have recently been published relating to vulnerabilities in network routers, including D-Link devices. 
These firmware updates address the security vulnerabilities in affected D-Link routers. D-Link will update this continually and we strongly recommend all users to install the relevant updates. 
As there are different hardware revisions on our products, please check this on your device before downloading the correct corresponding firmware update."

These Updates include the following Prototypes as of 28/11/13:



  • DI-524 

Revision E1/E3
The new firmware 5.13b01 that fixes the security vulnerabilities
Download Link
Please note: Unzip the file and use the file DI524Ex_FW513B01.bin to update firmware


  • DI-524UP 

Revision A1/A2
The new firmware 1.08b02 that fixes the security vulnerabilities
Download Link
Please note: Unzip the file and use the file DI524UPAx_FW108B02.bix to update firmware


  • DIR-100 

Revision A1
The new firmware 1.14b02 that fixes the security vulnerabilities
Download Link
Please note: Unzip the file and use the file DIR100A1_FW114WWB02.bix to update firmware


  • DIR-120 

Revision A1
The new firmware 1.05b02 that fixes the security vulnerabilities
Download Link
Please note: Unzip the file and use the file DIR120A1_FW105WWB02.bix to update firmware
As well for:


  • DI-604S
  • DI-604UP
  • DI-604+
  • TM-G5240
  •  
    BESIDES OTHER (CVE) For D-Link:


    Source: Techgeek

    For more detailed Information on that subject and about the Researcher(s) who detected the Vulnerability, please visit: Krebs on Security (Thx to Brian for posting this)