Saturday, December 14, 2013

Microsoft December Patch Tuesday fixes 24 vulns

Microsoft on last Tuesday released fixes for critical vulnerabilities in Internet Explorer, Microsoft Office, SharePoint, and the Windows operating system, including patches for two different zero-day vulnerabilities. But it has yet to patch a zero-day vulnerability that was first spotted in late November. The fixes came as part of Microsoft's regular patch-release cycle, which this month addressed 24 different vulnerabilities, as documented in 11 Microsoft security bulletins. Five of those bulletins were rated as "critical," meaning the flaws could be exploited remotely by attackers to take full control of a vulnerable system. Multiple information security experts have recommend starting with the fix for a zero-day Microsoft Graphics component memory corruption vulnerability (CVE-2013-3906), which was first discovered in early November via in-the-wild attacks. "The vulnerability could allow a remote-code execution if a user views TIFF files in shared content," said Microsoft. Exploit code for this bug has also already been built into the open-source Metasploit penetration testing tool. <more>

Chrome OS eyes on Password-free authentication

Google has a vision for how Chrome OS users will one day be able to lock and unlock their devices, without requiring a password. The Chromium OS team is building support for unlocking and locking devices running the operating system with a new Chrome API called "chrome.screenlockPrivate." The API was first spotted by developer and Google open-source Chromium evangelist François Beaufort, who points to a Chromium code review with a very short description: "The chrome.screenlockPrivate API allows select apps to control the ChromeOS ScreenLocker." Thankfully, it also includes a Google Docs link titled "chrome.screenlockPrivate - New Chrome API Proposal." <more>

Saturday, December 7, 2013

Google's Nexus phones vulnerable to SMS attacks

Google is reportedly looking into a problem with the latest versions of Nexus smartphones that could force the devices to restart, lock or fail to connect to the Internet. All Galaxy Nexus, Nexus 4 and Nexus 5 devices that run Android 4.0 contain a flaw that can render the phones vulnerable to a denial-of-service attack when a large number of Flash SMS messages are sent to them. According to a description on the programming site Stack Overflow, Flash SMS messages, also known as Class 0 SMS, are messages that show up - or flash - on screens immediately and dim the screen around the text. The messages are part of the GSM messaging infrastructure and are often used for sending emergency messages. Since the messages are not saved in phone's inboxes by default and simply appear, users can select to read or dismiss them. If a message is received on top of another however, they can stack up quickly. <more>