Friday, November 28, 2014

Google patches 42 flaws for Chrome

Google rolls out Chrome 39.0.2171.65 that fixes 42 security flaws in the web browser. Google Chrome now supports Apple Mac OS X running on 64-bit. Google has rewarded $41,500 to cyber security researchers for 12 security flaws reported. Researcher identified as "biloulehibou" got the highest reward of $7,500 for finding out an issue related to Adobe Flash player used in Chrome. Adobe advisory covered this issue under "double-free" vulnerability that allows intruders to execute arbitrary code. Chen Zhang of the NSFocus Security Team rewarded $5,500 for finding two bugs in the Blink rendering engine and Pepper plug-in interface used by Chrome. These issues are related to use-after-free vulnerabilities that allow remote code execution or possibly crash the vulnerable application. Latest version of Google Chrome disable fallback support for SSL 3.0 due to POODLE vulnerability. <more>

Friday, November 21, 2014

BIG Patch Tuesday fixes 33 vulns

November Patch Tuesday contains 14 security bulletins providing fixes for 33 vulnerabilities affecting all versions of Windows. Out of 14 bulletins, 4 bulletins are rated 'CRITICAL' whereas 8 bulletins declared 'Important' and the remaining 2 bulletins indicate moderate level severity. MS14-065 bulletin addresses 17 vulnerabilities affecting Internet Explorer. Most of the vulns are related to memory corruption and allows remote code execution by enticing a user to view malformed webpage. A vulnerability related to OLE which was previously exploited during Sandworm campaign is also patched under the CVE-2014-6352. A security flaw in the TCP/IP stack in Windows Server that allows remote attackers to execute arbitrary code on the vulnerable system is also patched along with other security bypass and privilege escalation issues. <more>

Apple devices HIT by Masque iOS malware

Security researchers at FireEye identified a new malware dubbed Masque targeting iOS devices. According to cyber security researchers, iOS versions 7.1.1, 7.1.2, 8.0, 8.1 and 8.1.1 beta enterprise provisioning features are vulnerable that means almost 95% devices are under attacked by this malware. Hui Xue, design engineer at FireEye believes that at the moment not many users are affected on large scale, but admit that in near future the scope can be widen. FireEye contacted vendor and they are working on it. FireEye advised users to download apps only from Apple App store and don't click on pop-ups. <more>