Showing posts with label critical. Show all posts
Showing posts with label critical. Show all posts
Friday, March 10, 2017
Java Critical Updates Apple Java 10 6 Update 15 Java 6u45 Apple Java 2013 002 Java 6u45 Oracle Java 7u21
Java Critical Updates Apple Java 10 6 Update 15 Java 6u45 Apple Java 2013 002 Java 6u45 Oracle Java 7u21
--[Updated 10:30 pm 2013-04-17 to reflect the correct version of Java provided by Apple, 6u45]
There was a scheduled Java update on Tuesday 2013-04-16. Both Apple and Oracle provided updates. Here is the list:
From Apple
1) Java for Mac OS X 10.6 Update 15
Available via Software Update. This updates Mac OS X 10.6 Snow Leopard users to Java version 6 update 45, aka 6u45.
Apples security content document:
http://support.apple.com/kb/HT5734
2) Java for OS X 2013-002
Available via Software Update. This updates OS X 10.7 Lion and 10.8 Mountain Lion users to Java version 6 update 45, aka 6u45.
Apples security content document:
http://support.apple.com/kb/HT5734
From Oracle
Java 7 update 21, aka 7u21
Available directly from Oracle via the link above.
Oracle Java SE Critical Patch Update Advisory - April 2013:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
PROBLEM WITH APPLES 2013-002 UPDATE
Apparently, it is NOT up-to-date!
Apple states that it is providing Java 6 update 45. However, their documentation is not listing the patching of all the known CVE security holes Oracle lists for Java 6 update 43 and below. I have documented the difference ahead.
[Note that earlier in the day it was not clear that Apple had updated beyond Java 6 update 43. Now apparently their documentation is making it clear that Java 6 update 45 is indeed what is provided. Apologies if I added to the confusion!]
Therefore, if you have OS X 10.7.3 or higher on you Mac, and you use Java while browsing the Internet, I STRONGLY suggest installing Oracles Java 7 update 21 (7u21) on top of Apples update.
Current Java CVE Issues
Oracles Java 7u21 patches 42 CVE security holes. Apples Java 6u45 patches 21 CVE security holes.
You can access Oracles Java SE Risk Matrix here:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html#AppendixJAVA
Im going to restate Oracles list of CVEs below in order to point out what has been patched and what remains unpatched in each of the updates from Oracle and Apple. Those that are in bold have been patched by both Oracles 7u21 update and Apples 6u42 update. Those in plain text have only been updated in Oracles 7u21 update. At the end of the list is one CVE in italics that was patched by Apples 6u42 update but is not listed in Oracles 7u21 update and remains listed but unspecified in the CVE databases. Those listed in red affect Java 7 only, not Java 6.

CVE-2013-2383
CVE-2013-2384
CVE-2013-1569
CVE-2013-2434
CVE-2013-2432
CVE-2013-2420
CVE-2013-1491
CVE-2013-1558
CVE-2013-2440
CVE-2013-2435
CVE-2013-2431
CVE-2013-2425
CVE-2013-1518
CVE-2013-2414
CVE-2013-2428
CVE-2013-2427
CVE-2013-2422
CVE-2013-1537
CVE-2013-1557
CVE-2013-2421
CVE-2013-0402
CVE-2013-2426
CVE-2013-2436
CVE-2013-1488
CVE-2013-2394
CVE-2013-2430
CVE-2013-2429
CVE-2013-1563CVE-2013-2439
CVE-2013-0401
CVE-2013-2419
CVE-2013-2424
CVE-2013-1561
CVE-2013-1564
CVE-2013-2438
CVE-2013-2417
CVE-2013-2418
CVE-2013-2416
CVE-2013-2433
CVE-2013-1540
CVE-2013-2423
CVE-2013-2415
CVE-2013-2437
Summary: If I can believe both Apple and Oracles lists of patched CVEs, this means that the following CVE security holes REMAIN in Apples Java 6u45 update:
CVE-2013-1518 - Unspecified details.
CVE-2013-2439 - Unspecified details.
CVE-2013-0401
Oracle Java 7 Update 17, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013.CVE-2013-2418 - Unspecified details.
Again note: Documentation confusion indicates these four CVEs were not patched by Apples Java 6u45 update. Ideally, Id like to verify that this is the fact in the near future. Im hoping this discrepancy in documentation is straightened out.
CONCLUSION:
If you want to surf the net with Java running, and youre using OS X 10.7.3 or higher, please install Apples Java 6u45 update FIRST, then install Oracles Java 7u21 update.
We know full well that there are still unpatched security holes in Java 7u21. Therefore, it is CRITICAL to Just Turn Java Off until you have loaded a trusted web page. Then turn Java ON and reload that page. Before you leave that page, Just Turn Java Off again. Ive covered how to turn Java on and off in previous posts.
STUPID NEWS:
Oracle has REMOVED the checkboxes for turning Java On and Off as of Java 7u21. Therefore, I cant rant about their dysfunctionality any longer, Oracle gave up trying to get their checkboxes to work, and apparently Oracle no longer even pretends there is a way to turn Java off inside its own control panel. Stupid deluxe. I have to wonder if Oracle itself understands Java well enough to get dead simple checkboxes to work.
I find this to be incredibly shameful.
Oracle: I HATE YOU.
And Apple: Either your documentation of patched CVEs is incomplete, or Oracle has provided an erroneous list of current CVEs! Either way, Id feel more secure knowing the four unpatched CVEs I list above actually had been patched by 6u45, or that they were actually inapplicable to 6u45. Im left confused as to the full state of affairs. No wonder newbies and regular users find these updates confusing.

--
Available link for download
Wednesday, December 28, 2016
Its Adobe Critical Updates Day! Flash AIR have 13 CVE patches Acrobat Reader have 51 patches!!!
Its Adobe Critical Updates Day! Flash AIR have 13 CVE patches Acrobat Reader have 51 patches!!!
--

Uninstall instructions from Adobe:
Uninstall Flash Player | Mac OS
Removing Adobe AIR
After uninstalling Flash and AIR, RESTART your running web browsers,
Please do this RIGHT NOW. If you have more than one Mac, be certain to dump Flash and AIR there as well.
More to follow.]
~ ~ ~ ~ ~
Its the second-Tuesday-of-the-month, which means its time for a bombardment of Adobe security patches! This months pile of patches is truly astonishing. Keep in mind that this isnt the only day of the month Adobe provides security updates. This past month, Adobe pushed out two separate groups of security updates.
Here are todays Adobe security bulletins:
Adobe Flash and AIR
Adobe Acrobat and Reader
Here are the linked Adobe updates:
Adobe Flash, Desktop v19.0.0.207
Adobe Flash, Extended Support v18.0.0.252 (Scroll down to Flash Player Archives)
Adobe AIR v19.0.0.213
Adobe Acrobat DC and DC Reader Continuous v2015.009.20069
Adobe Acrobat DC and DC Reader Classic v2015.006.30094
Adobe Acrobat and Reader XI Desktop v11.0.13
Adobe Acrobat and Reader X Desktop v10.1.16
CVE Patches:
[Im not linking the listed CVEs (Common Vulnerabilities and Exposures) this month as the list is massive and Im rather busy at my end at the moment. The link to look up CVEs is at the right of this page.]
Adobe Flash and AIR
Vulnerability DetailsAdobe Acrobat and Reader
These updates resolve a vulnerability that could be exploited to bypass the same-origin-policy and lead to information disclosure (CVE-2015-7628).
These updates include a defense-in-depth feature in the Flash broker API (CVE-2015-5569).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-7629, CVE-2015-7631, CVE-2015-7643, CVE-2015-7644).
These updates resolve a buffer overflow vulnerability that could lead to code execution (CVE-2015-7632).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-7625, CVE-2015-7626, CVE-2015-7627, CVE-2015-7630, CVE-2015-7633, CVE-2015-7634).
Vulnerability Details
These updates resolve a buffer overflow vulnerability that could lead to information disclosure (CVE-2015-6692).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-6689, CVE-2015-6688, CVE-2015-6690, CVE-2015-7615, CVE-2015-7617, CVE-2015-6687, CVE-2015-6684, CVE-2015-6691, CVE-2015-7621, CVE-2015-5586, CVE-2015-6683).
These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-6696, CVE-2015-6698).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-6685, CVE-2015-6693, CVE-2015-6694, CVE-2015-6695, CVE-2015-6686, CVE-2015-7622).
These updates resolve memory leak vulnerabilities (CVE-2015-6699, CVE-2015-6700, CVE-2015-6701, CVE-2015-6702, CVE-2015-6703, CVE-2015-6704, CVE-2015-6697).
These updates resolve security bypass vulnerabilities that could lead to information disclosure (CVE-2015-5583, CVE-2015-6705, CVE-2015-6706, CVE-2015-7624).
These updates resolve various methods to bypass restrictions on Javascript API execution (CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-7614, CVE-2015-7616, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, CVE-2015-7623, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715).

As ever, running software over the Internet can be dangerous. The most dangerous software to use are the Adobe Flash, Adobe Shockwave and Oracle Java browser plug-ins. If you dont need them, either trash them or pull them out of your system and put them intp a disabled folder. You can find all of these plug-ins here:
/Library/Internet Plug-ins/
Adobe Acrobat and Reader can be dangerous if youre using them to read PDF files youve downloaded from the Internet. The safest way to run either of these programs is with Enhanced Security (Security Enhanced) turned ON in their preferences. Even then, as noted in the CVE list above, that may not protect you from malicious PDF files.
Also dangerous, for the same reason, are the Adobe PDF Viewer plug-ins for web browsers. As with the other dangerous plug-ins noted above, either trash them or put them into a disabled folder. If you have a specific reason to use the Viewer plug-ins, then youre stuck with them. However, for the vast majority of people there is NO reason to use them. All web browsers have their own built-in PDF viewer functions. You can find the Adobe PDF Viewer plug-ins here:
/Library/Internet Plug-ins/AdobePDFViewer.plugin
/Library/Internet Plug-ins/AdobePDFViewerNPAPI.plugin
~ ~ ~ ~ ~

The #1 Rule of Computing and Security is:
MAKE A BACKUP!
Backups allow you to restore your computer back to health if it gets PWNed (zombied/botted) or otherwise compromised on the Internet.
There are many articles on the Internet about computer backup strategies. Here are a three articles and two ebooks specific to Mac backups:
Bulletproof backups: When you absolutely cant lose any data
Apple: Backing up your Mac hard drive
Apple Support Communities: Most commonly used backup methods
Backing Up Your Mac: A Joe On Tech Guide
TAKE CONTROL OF Security for Mac Users
Stay safe out there kids!

--
Available link for download
Monday, December 19, 2016
Java Out of Band Critical Security Update
Java Out of Band Critical Security Update
Oracle released an out-of-band critical security update which addresses CVE-2016-0603 which can be exploited when installing Java SE 6, 7 or 8 on the Windows platform.
Important Note: The exposure exists only during the installation process. Thus, Java SE users who have downloaded any old version of Java SE prior to 6u113, 7u97 or 8u73 for later installation needs to discard the old downloads and replace them with 6u113, 7u97 or 8u73 or later.
The Java SE Advanced Enterprise installers are not affected.
Download Information
Download link: Java SE 8u73Java SE 8u74, which is a "patch-set" update, including all of 8u73 plus additional features can be found here. Select the appropriate version for your operating system.
Verify your version: http://www.java.com/en/download/testjava.jsp
Notes:
- UNcheck any pre-checked toolbar and/or software options presented with the update. They are not part of the software update and are completely optional.
- Starting with Java SE 7 Update 21 in April 2013, all Java Applets and Web Start Applications should be signed with a trusted certificate. It is not recommended to run untrusted/unsigned Certificates. See How to protect your computer against dangerous Java Applets
Critical Patch Updates
The next scheduled dates of Oracle Java SE Critical Patch Updates are as follows:- 19 April 2016
- 19 July 2016
- 18 October 2016
- 17 January 2017
References
- Java SE 8u73 Update Release Notes
- Java SE 8u74 Update Release Notes
- Oracle Security Alert for CVE-2016-0603
- Java, The Never-Ending Saga
- Oracle Quality Assurance Blog
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Available link for download
Subscribe to:
Posts (Atom)