Thursday, April 08, 2010

April 2010 Bulletin Release Advance Notification

On Tuesday April 13, 2010, Microsoft will release 11 bulletins addressing 25 vulnerabilities in Windows, Microsoft Office, and Microsoft Exchange.

In addition, Microsoft will be closing the following open Security Advisories with next week’s updates:

· Microsoft Security Advisory (981169) - Vulnerability in VBScript Could Allow Remote Code Execution.

· Microsoft Security Advisory (977544) - Vulnerability in SMB Could Allow Denial of Service

Please also note the included reminder in the MSRC blog post that products/service packs will no longer receive security updates.

  • Windows XP Service Pack 2 will no longer be supported after July 13, 2010. Many customers are still on this version, so we encourage upgrading to Service Pack 3 or to Windows 7 as soon as possible.
  • Extended support for Windows 2000 will also be retired as of July 13, 2010. After that time, we will no longer provide security or any other updates for Windows 2000.
  • Windows Vista RTM will no longer be supported after the April 13, 2010 bulletin release. Service Pack 1 will still be supported until July 12, 2011 but we recommend customers update to Service Pack 2 or Windows 7 at this time.


References:


Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, April 03, 2010

Happy Easter

My husband is from Ukraine so we celebrate Easter according to Ukrainian traditions. What ever traditions you follow, I wish you a Happy Easter.




"Khrystos Voskres!"

(Christ is Risen!)






"Voistyno Voskres!"

(He is Truly Risen!)










Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, April 02, 2010

Mozilla Firefox 3.6.3 Security Update

Mozilla released Firefox version 3.6.3 to fix the vulnerability Nils used at CanSecWest to "take down" Firefox in the Pwn2Own Event (See Pwn2Own hack topples Firefox on Windows).



Security Advisory
"Title: Re-use of freed object due to scope confusion
Impact: Critical
Announced: April 1, 2010
Reporter: Nils (MWR InfoSecurity)
Products: Firefox

Fixed in: Firefox 3.6.3

Description

A memory corruption flaw leading to code execution was reported by security researcher Nils of MWR InfoSecurity during the 2010 Pwn2Own contest sponsored by TippingPoint's Zero Day Initiative. By moving DOM nodes between documents Nils found a case where the moved node incorrectly retained its old scope. If garbage collection could be triggered at the right time then Firefox would later use this freed object.


Note: The contest winning exploit only affects Firefox 3.6 and not earlier versions. We will be patching Firefox 3.5 in an upcoming release just in case there is an alternate way of triggering the bug."

References:

Clubhouse Tags: Clubhouse, Security, Vulnerabilities, Updates, Information






Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...