Friday, September 26, 2014

Apple iOS 8 fixes 53 vulns

Apple has released the latest version of iOS 8, fixing 53 vulnerabilities. Among these vulnerabilities, the most sever 'security threats' allow code execution with root privileges. Similarly other flaws can be exploited to execute arbitrary code with kernel or system privileges. Most vulnerabilities affect the WebKit browser engine that can be exploited when a victim is enticed to visit a specially crafted web page. iOS 8 minimize the threat of stealing Wi-Fi credentials by disabling the Lightweight Extensible Authentication Protocol (LEAP) which was not disabled by default in the earlier versions. <more>

Android flaw puts privacy at risk

According to security researcher Rafay Baloch, Android versions prior to 4.4 are prone to security bypass issue that allows intruders to gain control of a user's sessions on other sites. The issue is actually related to XSS flaw due to improper handling of javascript: strings preceded by a null byte character in the browser, which hampered the enforcement of same-origin policy. After the 'exploit' released under a Metasploit module by Rapid7 team, Google has acknowledged it and start working on a 'security patch' for earlier version KitKat. <more>

Friday, September 19, 2014

September’s PATCH TUESDAY fixes 42 flaws

On September 9th, Patch Tuesday fixes 42 security flaws covering Windows, Internet Explorer, .NET Framework, and Lync Server. This month Patch Tuesday contains a total of FOUR different bulletins, one of which was rated as CRITICAL. Internet Explorer (IE) has clinched the limelight by addressing 37 vulnerabilities under MS14-052 bulletin. Where as MS14-053 and MS14-055 fix Denial of Service (DoS) issues in the .Net framework and Lync Server respectively. MS14-054 security update addresses a vulnerability in Microsoft Windows Task Scheduler that allows attackers to gain elevated privileges via a crafted application. <more>