Tuesday, October 18, 2011

Oracle Java SE Critical Security Update

java

Oracle Java released a critical security update to Java Runtime Environment (JRE).  The full internal version number for this update release is 1.6.0_29-b11 (where "b" means "build"). The external version number is 6u29.

The critical update is a collection of patches for multiple security vulnerabilities in Oracle Java SE.  The update includes twenty (20) new security vulnerability fixes, of which six (6) are applicable to JRockit.

The update to Java SE 6u29 follows Java SE 6u27. Java SE 6u28 was used as an internal build and by-passed in favor of the current release of Java SE 6u29.

Although Java is not required (See Do You Need Java?), if you do have Java installed on your computer, it is advisable to install the latest update.  It is also advised that all prior (and vulnerable) versions of Java SE be uninstalled from your computer.

Download Update: Java SE Runtime Environment 6u29


Note: UNcheck any pre-checked toolbar and/or software options presented with the update. They are not part of the software update and are completely optional.


Affected Java SE Products and Components

  • JDK and JRE 7
  • JDK and JRE 6 Update 27 and earlier
  • JDK and JRE 5.0 Update 31 and earlier
  • SDK and JRE 1.4.2_33 and earlier
  • JavaFX 2.0
  • JRockit R28.1.4 and earlier(JDK and JRE 6 and 5.0)
The next scheduled Oracle Java SE Critical Patch Update is 14 February 2012.

    References






    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    SUPERAntiSpyware Adds Opt-in Toolbar

    Personally, I prefer not to use toolbars.  However, there are many people who like add-on toobars on their browser of choice.

    Something that has been a point of contention, particularly within the security community, is the inclusion of pre-checked toolbars with security software.  This practice has resulted in discontinuing recommendations for those programs, even though the software is offered free for personal use.

    SUPERAntiSpyware has apparently found it necessary to supplement the support of the free version of SUPERAntiSpyware by the inclusion of the Ask Toolbar.  The difference between the inclusion of the toolbar by SUPERAntiSpyware and other vendors is that it is opt-in rather than opt-out (pre-checked).




    Nick Skrepetos*, developer of SUPERAntiSpyware, provided the statement below at Wilders Security Forums:
    "It's not bundled, but rather an optional install that, if elected, enables a Professional feature - scheduled scanning at no charge. A "bundle" means it's included and installed as part of the package - we have an optional install. Nothing is disabled or features lost if the user elects not to install - it's still the great free SUPERAntiSpyware we have always produced!"

    Recommendation


    If SUPERAntiSpyware is your anti-malware software program of choice, consider purchasing a license for the software.  However, if your preference is to continue using the free version, the built in Windows Scheduler is an option to use in order to schedule scanning.

    *SUPERAntiSpyware was acquired by Support.com in June, 2011. Press Release: Support.com Expands Software Offerings With Acquisition of SUPERAntiSpyware


    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Tuesday, October 11, 2011

    Microsoft October 2011 Security Bulletin Release


    Microsoft released eight (8) bulletins addressing vulnerabilities in Internet Explorer, .NET Framework & Silverlight, Microsoft Windows, Microsoft Forefront UAG, and Microsoft Host Integration Server.  Two of the bulletins are rated Critical and six are rated Important

    Note:  With the inclusion of .NET Framework updates, it is recommended that those updates be installed separately from the remaining updates.  This is due to issues many people experience when installing .NET Framework updates.  Shutdown/restart the computer to complete the installation.

    Below are the Bulletins identified as Critical.  As noted above, it is recommended that MS11-078 be installed separately.

    • MS11-081 (Internet Explorer): This security update resolves eight privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.
    • MS11-078 (.NET Framework & Silverlight): This security update resolves a privately reported vulnerability in Microsoft .NET Framework and Microsoft Silverlight. The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.
    .

    Although the Executive Summaries indicate that some of the updates "may" require a restart, regardless of the recommendation, it is always best to restart your computer after applying updates.

    Support

    The following additional information is provided in the Security Bulletin:
    • The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
    • Customers in the U.S. and Canada can receive technical support from Security Support or 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates. For more information about available support options, see Microsoft Help and Support.
    • International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit International Help and Support.

    References





    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...