Tuesday, August 11, 2009

Java SE Runtime Environment 6u16 Update

Sun Microsystems has released update Java SE 6u16. This update does not contain any new fixes for security vulnerabilities. If you have already installed Java SE 6 Update 15, you have the latest security fixes and do not need to upgrade to this release to be current on security fixes.

From the Release Notes, BugID: 6862295, JDWP threadid changes during debugging session (leading to ignored breakpoints) was fixed in this update.

In the event you have any old Java updates prior to 6u10, it is strongly advised that you go to Add/Remove programs and uninstall those versions as the "update mechanism" did not remove those vulnerable versions. Following the uninstall, run JavaRa. Merely unzip JavaRa to your desktop and do the following:
  • Double-click on JavaRa.exe to start the program. (Windows Vista users right-click JavaRa.exe > Select Run as Administrator)
  • Click on Remove Older Versions to remove older versions of Java.
Download Link: Java SE Runtime Environment 6u16.

Note: uncheck any pre-checked toolbar and/or software options presented with the update. They are not part of the software update and are completely optional.)





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

August 2009 Bulletin Release

Microsoft released the new security bulletins listed below to resolve critical problem vulnerabilities. In addition to the new bulletins, Microsoft has released one new security advisory, one updated security advisory and two revised security bulletins.

Updated Security Advisory:
Microsoft updated Security Advisory 973882 - Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution.
Revised Security Bulletins:
  • Security Bulletin MS09-029 - Vulnerabilities in the Embedded OpenType Font Engine Could Allow Remote Code Execution (961371)
  • Security Bulletin MS09-035 - Vulnerabilities in Visual Studio Active Template Library Could Allow Remote Code Execution (969706)
New Security Bulletins:

Critical:
  • MS09-043
    Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)
  • MS09-044
    Vulnerabilities in Remote Desktop Connection Could Allow Remote Code Execution (970927)
  • MS09-039
    Vulnerabilities in WINS Could Allow Remote Code Execution (969883)
  • MS09-038
    Vulnerabilities in Windows Media File Processing Could Allow Remote Code Execution (971557)
  • MS09-037
    Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)
Important:
  • MS09-041
    Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)
  • MS09-040
    Vulnerability in Message Queuing Could Allow Elevation of Privilege (971032)
  • MS09-036
    Vulnerability in ASP.NET in Microsoft Windows Could Allow Denial of Service (970957)
  • MS09-042
    Vulnerability in Telnet Could Allow Remote Code Execution (960859)

References:


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, August 06, 2009

August 2009 Advance Notification

On August 11, 2009, Microsoft is planning to release nine new security bulletins. Below is a summary. Note that all bulletins require a restart except Bulletin 8. However, after installing updates, it is always recommended to restart the computer.

The full version of the Microsoft Security Bulletin Advance Notification for this month can be found at http://www.microsoft.com/technet/security/bulletin/ms09-aug.mspx. Jerry Bryant's report at the MSRC Blog is at August 2009 Advance Notification

Critical:

Bulletin 1
  • Vulnerability Impact: Remote Code Execution
  • Restart Requirement: May require restart
  • Affected Software: Microsoft Office, Microsoft Visual Studio, Microsoft ISA Server, and Microsoft BizTalk Server.
Bulletin 2
  • Vulnerability Impact: Remote Code Execution
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Remote Desktop Connection Client for Mac.
Bulletin 3
  • Vulnerability Impact: Remote Code Execution
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows 2000 Server and Windows Server 2003
Bulletin 4
  • Vulnerability Impact: Remote Code Execution
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.
Bulletin 5
  • Vulnerability Impact: Remote Code Execution
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.

Important:

Bulletin 6
  • Vulnerability Impact: Elevation of Privilege
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.
Bulletin 7
  • Vulnerability Impact: Elevation of Privilege
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003, and Windows Vista.
Bulletin 8
  • Vulnerability Impact: Denial of Service
  • Restart Requirement: Does not require restart
  • Affected Software: Microsoft .NET Framework on Windows Vista and Windows Server 2008.
Bulletin 9
  • Vulnerability Impact: Remote Code Execution
  • Restart Requirement: Requires restart
  • Affected Software: Microsoft Windows 2000, Windows XP, Windows Server 2003




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...