Google Search

Showing posts with label ships. Show all posts
Showing posts with label ships. Show all posts

Tuesday, December 3, 2013

Oracle ships giant raft of patches – but none of them for Java

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Oracle's latest Patch Tuesday has come and gone, with the database-and-more behemoth putting out patches for 89 vulnerabilities.

Twelve products sets in the Oracle stable get from 1 to 21 patches each.

These squash a total of 45 RCEs, or Remote Code Execution vulnerabilities.

In Oracle's own words, which are actually well chosen and plainly put, RCEs are defined as:

vulnerabilities [that] may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.

The affected product suites are listed below. (Oracle and Sun Systems Products, by the way, means Solaris, if you remember that.)

Oracle Enterprise Manager Grid ControlOracle Supply Chain Products SuiteOracle and Sun Systems Products

The one Oracle product conspicuous by its absence from this list is Java.

That's because Java is still on its own once-in-four-months update schedule, and received its most recent Critical Patch Update (CPU) last month.

This should be the last time this that Java will have to march to the tune of its own drum.

October 2013 is Oracle's annual "patchinox", when patches for Java and the rest of Oracle's products coincide.

The company has said that from then on, all non-emergency Critical Patch Updates will take place quarterly, at the same time.

Follow @duckblog


View the original article here

Friday, August 23, 2013

Apple ships jolly uninteresting iOS 6.1.4 update

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Apple's operating system updates, even the point releases, usually have quite a lot going for them.

(A point release is when only the number after the rightmost dot, or point, in the version string changes.)

For example, when OS X 10.8.2 was superseded by 10.8.3, Apple patched 21 security vulnerabilities.

Eleven of these vulnerabilities offered the possibility of remote code execution (RCE) exploits.

RCE holes are what make drive-by downloads possible, where you may end up getting infected merely by looking at a website, reading an email or viewing a document.

And when iOS 6.1.3 came out, we recommended it because it closed the door on a lock-screen bug that allowed you unlock an iPhone 5 without the passcode.

Just over a month later, and Apple has shipped iOS 6.1.4.

This time, though, there don't seem to be any security fixes - not even for the lock-screen bug that was found in iOS 6.1.3, the update that fixed a lock-screen bug.

Note that this update is for the iPhone 5 only, so owners of iPods, iPads and earlier iPhones won't be getting anything.

By the way, even if you do have an iPhone 5 and apply the update, assume that the iOS 6.1.3 lock-screen bug persists.

With that in mind, let me repeat our advice from March.

Make sure voice dialling is turned off, since the bypass trick only works if it is turned on.

Mind you, does anyone still voluntarily use voice dialling?

Surely you gave it up after the first time this happened:

A: [gossiping in the car] You know that odious chap, don't you?

B: Who?

A: That bloke CALLed JOHNATHAN [*]

Mobile phone: [inaudible over car noise] Do you want to call Johnathan?

B: I know him, YES.

Mobile phone: [inaudible] Calling Johnathan

B: That guy who thinks butter wouldn't melt?

Jonathan: [tinny, inaudible] Hello, Johnathan here.

A: Well, let me tell you something you didn't know about JOHNATHAN.

Jonathan: [tinny, inaudible] Yes, this is Jonathan.

A: Are you listening, because this is juicy!

Jonathan: [tinny, inaudible] Go ahead.

Since the primary purpose of iOS 6.1.4 seems to be to improve speakerphone voice quality, there's one more reason to turn voice dialling off!

Follow @duckblog

[*] Name changed for security reasons.


View the original article here

Sunday, May 26, 2013

Apple ships OS X 10.8.3 - 11 remote code execution vulns patched, Snow Leopard and Lion get fixes too

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Apple has shipped the latest point release of its flagship Mountain Lion operating system.

This brings current-version Mac users to OS X 10.8.3.

You can upgrade in three ways:

Let Apple's own Software Update from the Apple menu take care of it via the App Store.Download a standlone updater (541MByte) to take you from 10.8.2 to 10.8.3Download the Combo updater (794MByte) to take you from any earlier OS X 10.8 flavour to 10.8.3

Unless you have a bandwidth-related reason not to go for the biggest download, I recommend you go for the Combo updater.

It's worth having around even if you only have one Mac, in case you need or want to reinstall Mountain Lion.

With the most recent Combo updater handy, you can install plain old OS X 10.8 and then leap in one bound to the latest point release.

Apple, as usual, links to its regular landing page for security updates, knowledgebase article HT1222.

But that page, as usual, is lagging behind the actual update situation, with the most recent entry (as at 2013-03-15T20:40UTC+11) being Apple's Java security fix from 04 March 2013.

? If anyone at Apple is reading this, please beg your product managers to reorganise their update workflow so that the security notifications go live at the same time as, or before, the actual updates are published. After all, you invite your users to visit HT1222 from the start; I suggest that it'll be much easier to persuade people to be early adopters if you have all your informational ducks in a row from the start.

Having said that, the version-specific security update page is live, and can be found at knowledgebase article HT5672.

On security grounds alone, the update sounds well worth applying quickly.

There are fixes for 21 CVE-listed vulnerabilities, 11 of which are documented as offering remote attackers the potential for arbitrary code execution.

There are also various fixes for problems relating to data leakage or incorrect authentication (which invariably leads to data leakage because it permits users to see things they shouldn't).

The most interesting bug-fix, however, is CVE-2013-0967, whereby "visiting a maliciously crafted website could allow a Java Web Start application to be launched automatically even if the Java plug-in is disabled."

It'll be something of a surprise for anyone who was relying on Apple's new-found strictness against Java to find that turning Java off in your browser didn't necessarily have the desired effect!

Since running Java applets exposes you to a whole additional raft of possible security holes, this fix reinforces my suggestion above that this is an update worth applying as soon as you can.

Another noteworthy update is that the amusing (if unfunny) "fIle colon slash slash slash" bug is now a thing of the past.

That was a flaw in Apple's background data recognition software, which aims to auto-highlight text such as URLs displayed by applications such as word processors, text editors, browsers and email clients.

If you typed "file colon slash slash slash" (which denotes a local URL, i.e. a file or directory on your computer) then you'd be OK.

But if you mixed the case in the word "file", for example as "FiLE", OS X would fail an overly-strict internal error check and the affected application would almost immediately crash.

Irritating, for sure. But not very severe, and in any case now a bug of the past.

Safari gets bumped up to version 6.0.3, just in case you hadn't already fetched that as a standalone update.

And Windows 8 can now much more easily be installed alongside OS X, thanks to an upgraded version of Boot Camp.

Lastly, if you have one of the newfangled Retina MacBook Pro laptops, the Mac-oriented website Macobserver.com claims that 10.8.3 will squeeze 20 minutes more out of your Mac's battery than 10.8.2 did.

That's about it.

As an early adopter, I grabbed the Combo update as soon as I could and applied it.

I haven't had any trouble...yet, so I'll give you a cautious "thumbs up" to go ahead right away.

If you're an early adopter too, and you've grabbed 10.8.3 already, please let us know in the comments how you got along.

Your observations will help those who are still nervous of large-sounding point updates to make up their minds...

Follow @duckblog

NB. The Snow Leopard (10.6.8) and Lion (10.7.5) updates aren't full-on point updates. They're designated Security Update 2013-001 instead, and include all the 10.8.3 security fixes mentioned above. Like all updates explicitly labeled "security update", they're implicitly recommended for immediate deployment.


View the original article here