Mozilla officially released the stable version of Firefox 31 for all supported platforms, integrating 11 security fixes, three of them being marked as critical. One of the major vulnerabilities corrected would allow exploitation of a WebGL crash with Cesium JavaScript library. Details about this glitch are not available at the moment, but Mozilla notes that it cannot be leveraged through email in the Thunderbird client because scripting is disabled. Another flaw refers to a use-after-free vulnerability when handling DirectWrite font. Exploiting it would be possible on Windows platform only, OS X and Linux remaining unaffected. <more>
Friday, July 25, 2014
Backdoor discovered in Apple iOS devices
A security researcher is claiming to have found a set of services in iOS that appear to be a firmware-level backdoor in iOS devices. What's more interesting is that Apple has, in a very non-Apple manner, responded to his claims by posting a support page about it. He claims that these are confirmations of the backdoors that he found in iOS and that Apple claims to use them for diagnostic and enterprise purposes. These backdoors can only be accessed by Apple (or anyone that has access to Apple's services) so they're mostly secure backdoors, but they are backdoors nonetheless. Most consumers are completely and wholly unaware that alternative pathways into their devices exist and can be exploited by anyone (in this case Apple) other than themselves. <more>
Saturday, July 19, 2014
Oracle patches 113 updates
Oracle has issued 113 fixes relating to products in nearly its entire services portfolio in its latest quarterly Critical Patch Update. Oracle announced the details of its July Critical Patch Update, which was released on Tuesday, via a threat advisory on its website. The advisory details fixes for key Oracle products and services, including Fusion Middleware, Database, Server, Hyperion, Enterprise Manager Grid Control, E-Business Suite, Supply Chain, PeopleSoft, Siebel CRM, Communications, Retail, MySQL, Virtualization, Sun Systems and Java SE (JSE). Oracle urged customers to update their systems as soon as possible: "Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible." <more>
Subscribe to:
Posts (Atom)