Tuesday, February 14, 2012

Microsoft February 2012 Security Bulletin Release


Microsoft released nine (9) bulletins, of which four bulletins are identified as Critical with the remaining five as Important.

The bulletins address vulnerabilities in Microsoft Windows and Microsoft Developer Tools And Software.  Most updates will require a restart to complete the installation.

A number of people have a problem with .NET Framework updates.  As MS12-016 updates .NET Framework, it is recommended that this update by installed separately, followed by a shutdown/restart.

The Security Research and Defense blog published several articles, located at the links below, regarding the updates:


Security Bulletins

Bulletin NumberBulletin TitleBulletin KB
MS12-008Vulnerabilities in Microsoft Windows 2660465
MS12-009Vulnerabilities in Microsoft Windows 2645640
MS12-010Vulnerabilities in Internet Explorer 2647516
MS12-011Vulnerabilities in Microsoft SharePoint 2663841
MS12-012Vulnerability in Microsoft Windows 2643719
MS12-013Vulnerability in Microsoft Windows 2654428
MS12-014Vulnerability in Microsoft Windows 2661637
MS12-015Vulnerabilities in Microsoft Office 2663510
MS12-016Vulnerabilities in .NET Framework and Silverlight 2651026

Support

The following additional information is provided in the Security Bulletin:
  • The affected software listed have been tested to determine which versions are affected. Other versions are past their support life cycle. To determine the support life cycle for your software version, visit Microsoft Support Lifecycle.
  • Customers in the U.S. and Canada can receive technical support from Security Support or 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates. For more information about available support options, see Microsoft Help and Support.
  • International customers can receive support from their local Microsoft subsidiaries. There is no charge for support that is associated with security updates. For more information about how to contact Microsoft for support issues, visit International Help and Support.

References





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Saturday, February 11, 2012

Mozilla Firefox 10.0.1 Critical Security Update


Mozilla quickly released Firefox 10.0.1, which includes a critical security update as well as a bug fix to a java-related issue which results in text input to become unresponsive (Bug 718939).

Security Update

MFSA 2012-10 use after free in nsXBLDocumentInfo::ReadPrototypeBindings
Impact: Critical
Announced: February 10, 2012
Reporter: Andrew McCreight, Olli Pettay
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 10.0.1
  Firefox ESR 10.0.1
  Thunderbird 10.0.1
  Thunderbird ESR 10.0.1
  SeaMonkey 2.7.1

      Known Issues

      The following items remain as known issues with this version release:
      • Two-digit browser version numbers may cause a small number of website incompatibilities (see 690287)
      • If you try to start Firefox using a locked profile, it will crash (see 573369)
      • For some users, scrolling in the main GMail window will be slower than usual (see 579260)
      • Some synaptic touch pads are unable to vertical scroll (see 622410)
      • Firefox notifications may not work properly with Growl 1.3 or later (see 691662)
        Unresolved on v10 Resolved in v11
      • Under certain conditions, scrolling and text input may be jerky (see 711900)

      Update

      The update to Firefox 10.0.1 will be offered through the browser update mechanism.  However, as the upgrade includes a critical security update, it is recommended that the update be applied as soon as possible.  To get the update now, select Help, About Firefox, Check for Updates.

      If you do not use the English language version, Fully Localized Versions are available for download.

      References




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Thursday, February 09, 2012

      Security Bulletin Advance Notification for February, 2012


      On Tuesday, February 14, 2012, Microsoft is planning to release nine (9) bulletins, of which four bulletins ares identified as Critical with the remaining five as Important.

      The bulletins address twenty-one (21) vulnerabilities in Microsoft Windows, Office, Internet Explorer, and .NET/Silverlight.  Most updates will require a restart to complete the installation.

      As happens each month, Microsoft will also release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

      References




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...