Tuesday, March 12, 2013

Microsoft Security Bulletin Release for March 2013


Microsoft released seven (7) bulletins.  Four bulletins are identified as Critical with three bulletins rated Important.

The critical bulletins address 20 vulnerabilities in Microsoft Windows, Office, Internet Explorer, Server Tools, and Silverlight.  The bulletins rated Important address issues in Microsoft Windows and Office.

With today's Windows Update, Internet Explorer 10 in Windows 8 and Windows RT is being updated to enable Flash content to run by default. On Windows 8, all Flash content continues to be enabled for IE on the desktop. Additional information is available in the IE Blog post, Flash in Windows 8.

Included in updates today is an update addressing an issue in the Kernel-Mode Drivers where an attacker could own your machine by inserting a malicious USB device.  In this scenario, logging on to the machine is not required.  Additional details about the update are available in the below-linked MSRC Blog post.

Bulletin NumberBulletin TitleBulletin KB
MS13-021Cumulative Security Update for Internet Explorer 2809289
MS13-022Vulnerability in Microsoft Windows 2814124
MS13-023Vulnerability in Microsoft Office 2801261
MS13-024Vulnerabilities in Microsoft Office 2780176
MS13-025Vulnerability in Microsoft Office 2816264
MS13-026Vulnerability in Microsoft Office 2813682
MS13-027Vulnerabilities in Microsoft Windows 2807986

Support

The following additional information is provided in the Security Bulletin:

References





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Critical Adobe Flash Player and Adobe AIR Update



Adobe Flash Player was updated today to address critical security vulnerabilities.  These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.
With today's Windows Update, Internet Explorer 10 in Windows 8 and Windows RT is being updated to enable Flash content to run by default. On Windows 8, all Flash content continues to be enabled for IE on the desktop. Additional information is available in the IE Blog post, Flash in Windows 8.


Update Information

The newest versions are as follows:
Windows and Macintosh:  11.6.602.180
Linux: 11.2.202.275
Android 4x:  11.1.115.48
Android 3x and lower:  11.1.111.44
Adobe AIR 3.6.0.6090

Release date: March 12, 2013
Vulnerability identifier: APSB13-09

CVE number: CVE-2013-0646, CVE-2013-0650, CVE-2013-1371, CVE-2013-1375
Platform: All Platforms

Flash Player Update Instructions


Flash Player for Windows, Macintosh and Linux

Although Adobe suggests downloading the update from the Adobe Flash Player Download Center or by using the auto-update mechanism within the product when prompted, if you prefer, direct download links are available.

Notes:
  • If you use the Adobe Flash Player Download Center, be careful to uncheck the optional McAfee Security Plus box.  It is not needed for the Flash Player update.
  • Uncheck any toolbar offered with Adobe products if not wanted.
  • If you use alternate browsers, it is necessary to install the update for both Internet Explorer as well as the update for alternate browsers.
  • The separate 32-bit and 64-bit uninstallers have been replaced with a single uninstaller.
Adobe Flash Player for Android

The latest version for Adobe Flash Player for Android is available by downloading it from the Android Marketplace by browsing to it on a mobile phone.   

Verify Installation

To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu. 

Do this for each browser installed on your computer.

To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.

References







Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, March 07, 2013

Mozilla Firefox 19.0.2 Security Update Due to Pwn2Own



The CanSecWest security conference is underway and Firefox fell along with others.  However, Mozilla developers quickly diagnosed the issue, built a patch, validated the fix and the resulting builds, and Firefox version 19.0.2 has been sent to the release channels.

What’s New

FIXED -- 19.0.2: Security-driven release, see details in the associated security advisory

Update

To get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu.

If you do not use the English language version, Fully Localized Versions are available for download.

References




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...