Patch Management

March 9, 2010, 2:38PM Threatpost Original

Microsoft Plugs Security Holes in Windows, Office

After a busy February with 13 security bulletins, Microsoft is easing off the patching throttle a bit this month. 

Microsoft released two new security bulletins addressing 8 vulnerabilities, all not publically known at this time. 

Shorten URL: http://threatpost.com/en_us/3ty. Click to copy to clipboard or post to Twitter

March 9, 2010, 2:26PM Threatpost Original

Microsoft Warns of New IE Zero Day Attacks

A zero-day (unpatched) vulnerability in Microsoft’s Internet Explorer is being exploited in the wild, the company warned in an advisory issued today.

On the same day it issued software fixes as part of its Patch Tuesday schedule, Microsoft released a pre-patch advisory to warn of the risk of remote code execution attacks against users of IE 6 and IE 7.

Shorten URL: http://threatpost.com/en_us/3tE. Click to copy to clipboard or post to Twitter

March 8, 2010, 5:10PM

Apache Web Server Has Serious Vulnerability

Apache's HTTP web server has a flaw that enables remote server access and total control of a database, according to a security researcher. Read the full article. [ZDNet Australia]

Shorten URL: http://threatpost.com/en_us/3eJ. Click to copy to clipboard or post to Twitter

March 5, 2010, 4:40PM

Opera Bug Can Crash Browser

A security vulnerability identified in Opera can be exploited to crash users' browsers, but probably can't lead to the remote execution of malware, a company spokesman said. Read the full article. [The Register]

Shorten URL: http://threatpost.com/en_us/3MQ. Click to copy to clipboard or post to Twitter

March 5, 2010, 12:49PM

Cisco Patches Voice Flaws

Cisco has released a number of reports on vulnerabilities in its products. It is possible to disrupt the transfer of voice data in the Unified Communications Manager using crafted SIP, SCCP and CTI packets. Read the full article. [The H Security]

Shorten URL: http://threatpost.com/en_us/3MB. Click to copy to clipboard or post to Twitter

March 5, 2010, 10:49AM

New PHP Maintenance Release Fixes 60 Bugs

A now available second maintenance release for PHP 5.3 fixes more than 60 bugs and closes several security holes which were already corrected in version 5.2.13, from the 5.2 branch, last week. Read the full article. [The H Security]

Shorten URL: http://threatpost.com/en_us/3Mj. Click to copy to clipboard or post to Twitter

March 5, 2010, 8:26AM

Software Patch Needed on Windows Every 5 Days

The average Microsoft Windows user has software from 22 vendors on her PC, and needs to install a new security update roughly every five days in order to use these programs safely, according to an insightful new study released this week. Read the full article. [KrebsonSecurity]

Shorten URL: http://threatpost.com/en_us/3M4. Click to copy to clipboard or post to Twitter

March 4, 2010, 2:51PM Threatpost Original

Microsoft to Patch 8 Vulnerabilities in Windows, Office

Microsoft has announced plans to ship two security bulletins next week to fix a total of eight vulnerabilities affecting Windows and Office products.

Both bulletins are rated "important" because of the risk compromising the confidentiality, integrity or availability of user data.

Shorten URL: http://threatpost.com/en_us/3L9. Click to copy to clipboard or post to Twitter

March 2, 2010, 4:15PM

MS' Blue Screen Fix MS10-015 Redistributed

Microsoft today said it had restarted distribution of a security update that had crippled some Windows PCs last month with reboot problems and Blue Screen of Death error screens. Read the full article. [Computerworld]

Shorten URL: http://threatpost.com/en_us/3FC. Click to copy to clipboard or post to Twitter

March 1, 2010, 3:07PM Threatpost Original

Google Researcher Ships Exploit to Defeat ASLR+DEP

A prominent security researcher has released an exploit that uses a new technique to defeat ALSR + DEP on Microsoft's Windows operating system.

The exploit, released by Google security researcher "SkyLined," uses the ret-into-libc technique to bypass DEP (Data Execution Prevention) and launch code execution attacks on x86 platforms. 

Shorten URL: http://threatpost.com/en_us/3Hs. Click to copy to clipboard or post to Twitter

Syndicate content

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy