<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; Security Vulnerability</title>
	<atom:link href="http://www.spamchronicles.com/category/security-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Microsoft Patch Tuesday for August 2007</title>
		<link>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/</link>
		<comments>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 19:26:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-august-2007/</guid>
		<description><![CDATA[Microsoft patch Tuesday for August 2007 brings us 6 critical and 3 important security updates from Microsoft. Microsoft summarizes the patches in their August summary. Every supported desktop version of Windows is affected by one or more patches. Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Microsoft patch Tuesday</b> for August 2007 brings us <b>6 critical</b> and <b>3 important</b> security updates from <b>Microsoft</b>. Microsoft <a href="http://www.microsoft.com/technet/security/bulletin/ms07-aug.mspx" title="Jump to the Microsoft article about the security patches">summarizes the patches</a> in their August summary. Every supported desktop version of Windows is affected by one or more patches.  Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. Microsoft Office for Mac also needs patching.</p>
<p>Rather than repeating all the patches I&#8217;ll direct you to news.com which has a <a href="http://news.com.com/8301-10784_3-9759611-7.html?tag=nefd.only" title="Jump to the news.com summary of the Microsoft patches">good summary of the patches</a> along with links to the individual bulletins. The patches are available through automatic updates or individual downloads.</p>
<p>Happy patching and good luck.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSX Security Update 2007-007</title>
		<link>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 02:32:39 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/osx-security-update-2007-007/</guid>
		<description><![CDATA[Apple almost made it through the month of July without an operating system security update which would have been a first for the year. But OS X Security Update 2007-007 was released on the last day of the month. Thirteen components are updated. Click the thumbnail to see the component list or visit the Apple [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/osxsecurityupdate2007-007.png" title="OS X Security Update 2007-007"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/osxsecurityupdate2007-007.thumbnail.png" alt="OS X Security Update 2007-007" align="left" /></a><b>Apple</b> almost made it through the month of July without an operating system security update which would have been a first for the year. But <b>OS X Security Update 2007-007</b> was released on the last day of the month.</p>
<p>Thirteen components are updated. Click the thumbnail to see the component list or visit the <a href="http://docs.info.apple.com/article.html?artnum=306172" title="Jump to the Apple support page for the update">Apple Support Page</a> for the complete details. Of special note is the Samba vulnerability that Apple has finally patched. Samba is an open source windows file sharing application that is bundled with OS X. A critical vulnerability was found in late may and almost immediately patched by the Samba team. Apple has released several security updates since then but none have included the Samba patch, until now. Samba is off by default but is enabled when turning on Windows sharing in System Preference -&gt; Sharing.</p>
<p>The update is for both Intel and PPC based Macs running OS X 10.3.9 or OS X 10.4.10 including the standard OS and the Server OS. It&#8217;s available through Apple&#8217;s built-in software update service or as a standalone download. A computer restart is needed after applying the patch.</p>
<p>Apple also released <a href="http://www.apple.com/support/downloads/airportextremeupdate2007004.html" title="Jump to the Airport Extreme Update support page">Airport Extreme Update 2007-004</a>. Details are lacking and Apple&#8217;s only comment is:</p>
<blockquote><p>This update is recommended for all Intel-based MacBook, MacBook Pro, and Mac mini computers and improves the reliability of AirPort connections.</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Stats Plugin Vulnerability Plugged</title>
		<link>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 20:25:10 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/wordpress-stats-plugin-vulnerability-plugged/</guid>
		<description><![CDATA[I usually don&#8217;t mention WordPress vulnerabilities here, but since I use WordPress and the vulnerable plugin I figured I&#8217;d mention it (now that I&#8217;m patched). The WordPress Stats plugin by Automattic (Andy Skelton ) had a critical SQL injection vulnerability that could allow admin credentials to be stolen. The vulnerability was patched in version 1.1.1 [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/wp_logo2.png" title="WordPress Logo in Blue"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/wp_logo2.png" alt="WordPress Logo in Blue" align="left" /></a>I usually don&#8217;t mention <b>WordPress </b>vulnerabilities here, but since I use WordPress and the vulnerable plugin I figured I&#8217;d mention it (now that I&#8217;m patched).</p>
<p>The <a href="http://wordpress.org/extend/plugins/stats/" title="Jump to the Plugin page on wordpress.org">WordPress Stats</a> plugin by Automattic (Andy Skelton ) had a critical SQL injection vulnerability that could allow admin credentials to be stolen. The vulnerability was patched in version 1.1.1 and was released July 27th.</p>
<p>I typically turn off (deactivate) plugins before updating them and in this case I had to re-enter the API key when activating the updated plugin.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/30/site-upgraded-to-wordpress-22/" rel="bookmark" class="crp_title">Site Upgraded to WordPress 2.2</a></li><li><a href="http://www.spamchronicles.com/2007/06/24/spam-counts-for-week-ending-june-24-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 24, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/06/03/spam-counts-for-week-ending-june-3-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 3, 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Firefox 2.0.0.6 Released</title>
		<link>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 13:04:47 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/mozilla-firefox-2006-released/</guid>
		<description><![CDATA[Mozilla has released a security update to Firefox 2, making it the second update this month. Firefox 2.0.0.6 is available through the built-in auto-update feature or as a standalone download. One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" /><b>Mozilla</b> has released a security update to <b>Firefox 2</b>, making it the second update this month. <a href="http://en-us.www.mozilla.com/en-US/firefox/2.0.0.6/releasenotes/" title="Jump to the Firefox 2.0.0.6 release notes">Firefox 2.0.0.6</a> is available through the built-in auto-update feature or as a <a href="http://getfirefox.com" title="Jump to the Get Firefox website">standalone download</a>.</p>
<p>One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to the vulnerability that was found when IE 7 passed a malformed URI to Firefox.</p>
<p>The moderate vulnerability is &#8220;Privilege escalation through chrome-loaded about:blank windows&#8221;. This was dependant on add-ons creating about:blank windows.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.5 Released</title>
		<link>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/#comments</comments>
		<pubDate>Wed, 18 Jul 2007 19:19:54 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/firefox-2005-released/</guid>
		<description><![CDATA[Mozilla has released Firefox 2.0.0.5 which patches eight security vulnerabilities in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities. Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" /><b>Mozilla</b> has released <b><a href="http://www.mozilla.com/en-US/firefox/2.0.0.5/releasenotes/" title="Jump to the Firefox 2.0.0.5 release notes">Firefox 2.0.0.5</a></b> which patches eight <b>security vulnerabilities</b> in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities.</p>
<p>Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating means:</p>
<blockquote><p>Vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.</p></blockquote>
<p>Two vulnerabilities were rated as &#8220;high&#8221; which means:</p>
<blockquote><p>Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.</p></blockquote>
<p>The remaining three vulnerabilities where rated as moderate (1) or low(2).</p>
<p>The update will be installed through Firefox&#8217;s auto-update feature. You can force an update check by going to the Help on the menu and selecting &#8220;Check for Updates&#8230;&#8221;. You can also download the full version from the website and run the installation over your current installation. The update is for all languages on all operating systems.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Patches Flash Player</title>
		<link>http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/</link>
		<comments>http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 16:07:01 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[software-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/adobe-patches-flash-player/</guid>
		<description><![CDATA[Adobe has issued an update to Flash Player (formerly known as Macromedia Flash Player) that patches several serious security vulnerabilities. The latest version is Flash Player 9.0.47.0 They&#8217;ve also updated the older version 7 to version 7.0.70.0. The patch may be installed through the auto update feature of Flash Player or you can visit the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Adobe</b> has issued an update to <b>Flash Player</b> (formerly known as Macromedia Flash Player) that patches several serious security vulnerabilities. The latest version is <b>Flash Player 9.0.47.0</b> They&#8217;ve also updated the older version 7 to version 7.0.70.0.</p>
<p>The patch may be installed through the auto update feature of Flash Player or you can visit the <a href="http://www.macromedia.com/software/flash/about/" title="Jump to the Flash - About page on Adobe">About Flash Player</a> page to see what version you have installed and download the update. You can also go directly to the Adobe Flash Player <a href="http://www.macromedia.com/go/getflash" title="Go to the Adobe Flash Player download page">download page</a>. If you run Flash under multiple browsers you&#8217;ll have to update the player for each browser. You&#8217;ll need to close all browser windows during the installation. The update is for Flash Player on both Windows and OS X.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/" rel="bookmark" class="crp_title">Mac Hacked &#8211; Both Sides Miss the Point</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Adds to Patch Tuesday</title>
		<link>http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/</link>
		<comments>http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 00:38:21 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[software-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/apple-adds-to-patch-tuesday/</guid>
		<description><![CDATA[Apple joins the the Tuesday patch party and releases a security update for Quicktime along with a bugfix update for iTunes. The patches are for the software on both Windows and OS X. The Quicktime update, to version 7.2 includes eight security vulnerability fixes some of which will allow code execution. It also includes updates [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Apple</b> joins the the Tuesday patch party and releases a security update for <b>Quicktime</b> along with a bugfix update for <b>iTunes</b>. The patches are for the software on both Windows and OS X.</p>
<p>The Quicktime update, to version 7.2 includes <a href="http://docs.info.apple.com/article.html?artnum=305947" title="Jump to the Apple article on the security fixes">eight security vulnerability fixes</a> some of which will allow code execution. It also includes updates to the H.264 codec, support for full screen viewing and &#8220;numerous bug fixes&#8221;.  The update requires a reboot on both Mac and Windows.</p>
<p>The iTunes update brings iTunes to 7.3.1 and fixes a problem with iTunes 7.3 accessing the library. No other changes are documented.</p>
<p>Both patches are available through Apple software update or from the <a href="http://www.apple.com/support/downloads/" title="Jump to the download page on the Apple website">Apple download</a> page.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/20/apple-tv-security-update/" rel="bookmark" class="crp_title">Apple TV Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for July 2007</title>
		<link>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/</link>
		<comments>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/#comments</comments>
		<pubDate>Wed, 11 Jul 2007 12:55:43 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-july-2007/</guid>
		<description><![CDATA[It&#8217;s the second Tuesday of July and that means patches from Microsoft. This month brings six patches, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" />It&#8217;s the second Tuesday of July and that means patches from <b>Microsoft</b>. This month brings <b>six patches</b>, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique patch although it&#8217;s the one rated moderate.</p>
<p>Two of the patches affect <b>Microsoft Office</b> software:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx" title="Jump to the MS07-036 bulletin at Microsoft">MS07-036</a> is rated <b>critical</b> and affects all versions of <b>Microsoft Excel </b>from Excel 2000 on up. It also applies to the Office 2007 compatibility pack. It&#8217;s only rated critical for Excel 2000. Microsoft rates the other versions as &#8220;important&#8221;. The bulletin does not list any known issues.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-037.mspx" title="Jump to the MS07-037 bulletin">MS07-037</a> is rated <b>important</b> and affects <b>Microsoft Office Publisher 2007</b> only. The bulletin does not list any known issues.</p>
<p>One patch affects Vista only:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-038.mspx" title="Jump to the MS07-038 bulletin">MS07-038</a> is rated <b>moderate</b> and affects <b>Windows Vista</b>, both 32-bit and 64-bit versions. This patches a vulnerability in the Windows Vista firewall that could allow an attacker to gather information about a host. There are no known issues listed in the bulletin.</p>
<p>One patch affects <b>.NET</b>:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx" title="Jump to the MS07-040 bulletin">MS07-040</a> is rated critical and affects .NET versions 1.x and 2.x, version 3.x is not affected. All operating systems are affected if they have a vulnerable version of .NET installed. There are no known issues listed in the bulletin.</p>
<p>The final desktop patch, <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-041.mspx" title="Jump to the MS07-041 bulletin">MS-07-041</a>, is rated important and affects Microsoft Internet Information Server (IIS) when running on Windows XP SP2. Earlier versions of Windows XP may be affected but Microsoft only supports service pack 2. IIS is not installed by default on Windows XP.</p>
<p>The server patch is is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-039.mspx" title="Jump to the MS07-039 bulletin">MS07-039</a> and is a vulnerability in Active Directory that&#8217;s rated critical.</p>
<p>The patches are available through automatic update or can be downloaded individually from Microsoft.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Pits Firefox Against IE</title>
		<link>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/</link>
		<comments>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/#comments</comments>
		<pubDate>Tue, 10 Jul 2007 22:52:23 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[internet-explorer]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/vulnerability-pits-firefox-against-ie/</guid>
		<description><![CDATA[A new zero-day vulnerability exists when both Firefox 2.x and Internet Explorer are installed on the same machine. The exploit is most likely to be available on PCs with Firefox 2.0.0.2 installed due to changes made for Microsoft Vista compatibility. The general consensus of the comments are that both applications contribute the the exploit. Firefox [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ielogo.png" alt="IE Logo" align="left" /><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" height="121" width="122" />A new <a href="http://larholm.com/2007/07/10/internet-explorer-0day-exploit/" title="Jump to to the entry on Larholm.com">zero-day vulnerability</a> exists when both Firefox 2.x and Internet Explorer are installed on the same machine. The exploit is most likely to be available on PCs with Firefox 2.0.0.2 installed due to changes made for Microsoft Vista compatibility.</p>
<p>The general consensus of the comments are that both applications contribute the the exploit. Firefox is the attack vector and fails to validate the malicious code but Microsoft contributes by not properly passing quotes to the command line. You need to visit a malicious website using IE in order to trigger the exploit.</p>
<p>In a response to a user comment Thor Larholm responded:</p>
<blockquote><p>&#8230; Firefox is the current attack vector but Internet Explorer is to blame for not escaping ” (quote) characters when passing on the input to the command line. I agree that Firefox could have registered its URL handler with pure DDE instead and thereby have avoided the possibility of a command line argument injection, but IE should still be able to safely launch external applications safely.</p></blockquote>
<p>What I find interesting is the complexity of the requirements leading to the exploit. Neither product is vulnerable alone since both must be installed and both products have a flaw that contributes to the vulnerability.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/" rel="bookmark" class="crp_title">Mac Hacked &#8211; Both Sides Miss the Point</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Update 2007-006 for Apple OS X</title>
		<link>http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/</link>
		<comments>http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/#comments</comments>
		<pubDate>Sat, 23 Jun 2007 23:55:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[osx]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/security-update-2007-006-for-apple-os-x/</guid>
		<description><![CDATA[Apple has released a security-only update for OS X. It&#8217;s the appropriately named Security Update 2007-006 as Apple has released one security update a month so far this year. This update is needed for 10.4.9 along with the just released 10.4.10. It&#8217;s also needed for 10.3.9. The security update addresses two vulnerabilities. One is in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/osx2007-006.png" title="OS X Security Update 2007-006"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/osx2007-006.thumbnail.png" alt="OS X Security Update 2007-006" align="left" /></a><b>Apple</b><b> </b>has released a security-only update for OS X. It&#8217;s the appropriately  named <a href="http://docs.info.apple.com/article.html?artnum=305759" title="Jump to the Apple support article about the update"><b>Security Update 2007-006</b></a> as Apple has released one security update a month so far this year. This update is needed for 10.4.9 along with the just released 10.4.10. It&#8217;s also needed for 10.3.9. The security update addresses two vulnerabilities.</p>
<p>One is in <b>Webcore</b> and can allow <b>cross-site scripting attacks</b>.</p>
<p>The second patched vulnerability was in <b>Webkit</b> and could allow remote code execution.</p>
<p>The update is available through Software Update or as a <a href="http://www.apple.com/support/downloads/" title="Jump to the Apple download page">standalone download</a> and requires a reboot.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/" rel="bookmark" class="crp_title">OSX Security Update 2007-007</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
