<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; software-security-patch</title>
	<atom:link href="http://www.spamchronicles.com/tag/software-security-patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Microsoft Patch Tuesday for August 2007</title>
		<link>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/</link>
		<comments>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 19:26:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-august-2007/</guid>
		<description><![CDATA[Microsoft patch Tuesday for August 2007 brings us 6 critical and 3 important security updates from Microsoft. Microsoft summarizes the patches in their August summary. Every supported desktop version of Windows is affected by one or more patches. Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Microsoft patch Tuesday</b> for August 2007 brings us <b>6 critical</b> and <b>3 important</b> security updates from <b>Microsoft</b>. Microsoft <a href="http://www.microsoft.com/technet/security/bulletin/ms07-aug.mspx" title="Jump to the Microsoft article about the security patches">summarizes the patches</a> in their August summary. Every supported desktop version of Windows is affected by one or more patches.  Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. Microsoft Office for Mac also needs patching.</p>
<p>Rather than repeating all the patches I&#8217;ll direct you to news.com which has a <a href="http://news.com.com/8301-10784_3-9759611-7.html?tag=nefd.only" title="Jump to the news.com summary of the Microsoft patches">good summary of the patches</a> along with links to the individual bulletins. The patches are available through automatic updates or individual downloads.</p>
<p>Happy patching and good luck.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Firefox 2.0.0.6 Released</title>
		<link>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 13:04:47 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/mozilla-firefox-2006-released/</guid>
		<description><![CDATA[Mozilla has released a security update to Firefox 2, making it the second update this month. Firefox 2.0.0.6 is available through the built-in auto-update feature or as a standalone download. One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" /><b>Mozilla</b> has released a security update to <b>Firefox 2</b>, making it the second update this month. <a href="http://en-us.www.mozilla.com/en-US/firefox/2.0.0.6/releasenotes/" title="Jump to the Firefox 2.0.0.6 release notes">Firefox 2.0.0.6</a> is available through the built-in auto-update feature or as a <a href="http://getfirefox.com" title="Jump to the Get Firefox website">standalone download</a>.</p>
<p>One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to the vulnerability that was found when IE 7 passed a malformed URI to Firefox.</p>
<p>The moderate vulnerability is &#8220;Privilege escalation through chrome-loaded about:blank windows&#8221;. This was dependant on add-ons creating about:blank windows.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.5 Released</title>
		<link>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/#comments</comments>
		<pubDate>Wed, 18 Jul 2007 19:19:54 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/firefox-2005-released/</guid>
		<description><![CDATA[Mozilla has released Firefox 2.0.0.5 which patches eight security vulnerabilities in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities. Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" /><b>Mozilla</b> has released <b><a href="http://www.mozilla.com/en-US/firefox/2.0.0.5/releasenotes/" title="Jump to the Firefox 2.0.0.5 release notes">Firefox 2.0.0.5</a></b> which patches eight <b>security vulnerabilities</b> in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities.</p>
<p>Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating means:</p>
<blockquote><p>Vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.</p></blockquote>
<p>Two vulnerabilities were rated as &#8220;high&#8221; which means:</p>
<blockquote><p>Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.</p></blockquote>
<p>The remaining three vulnerabilities where rated as moderate (1) or low(2).</p>
<p>The update will be installed through Firefox&#8217;s auto-update feature. You can force an update check by going to the Help on the menu and selecting &#8220;Check for Updates&#8230;&#8221;. You can also download the full version from the website and run the installation over your current installation. The update is for all languages on all operating systems.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Patches Flash Player</title>
		<link>http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/</link>
		<comments>http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 16:07:01 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[software-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/adobe-patches-flash-player/</guid>
		<description><![CDATA[Adobe has issued an update to Flash Player (formerly known as Macromedia Flash Player) that patches several serious security vulnerabilities. The latest version is Flash Player 9.0.47.0 They&#8217;ve also updated the older version 7 to version 7.0.70.0. The patch may be installed through the auto update feature of Flash Player or you can visit the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Adobe</b> has issued an update to <b>Flash Player</b> (formerly known as Macromedia Flash Player) that patches several serious security vulnerabilities. The latest version is <b>Flash Player 9.0.47.0</b> They&#8217;ve also updated the older version 7 to version 7.0.70.0.</p>
<p>The patch may be installed through the auto update feature of Flash Player or you can visit the <a href="http://www.macromedia.com/software/flash/about/" title="Jump to the Flash - About page on Adobe">About Flash Player</a> page to see what version you have installed and download the update. You can also go directly to the Adobe Flash Player <a href="http://www.macromedia.com/go/getflash" title="Go to the Adobe Flash Player download page">download page</a>. If you run Flash under multiple browsers you&#8217;ll have to update the player for each browser. You&#8217;ll need to close all browser windows during the installation. The update is for Flash Player on both Windows and OS X.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/" rel="bookmark" class="crp_title">Mac Hacked &#8211; Both Sides Miss the Point</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Adds to Patch Tuesday</title>
		<link>http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/</link>
		<comments>http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 00:38:21 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[software-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/apple-adds-to-patch-tuesday/</guid>
		<description><![CDATA[Apple joins the the Tuesday patch party and releases a security update for Quicktime along with a bugfix update for iTunes. The patches are for the software on both Windows and OS X. The Quicktime update, to version 7.2 includes eight security vulnerability fixes some of which will allow code execution. It also includes updates [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Apple</b> joins the the Tuesday patch party and releases a security update for <b>Quicktime</b> along with a bugfix update for <b>iTunes</b>. The patches are for the software on both Windows and OS X.</p>
<p>The Quicktime update, to version 7.2 includes <a href="http://docs.info.apple.com/article.html?artnum=305947" title="Jump to the Apple article on the security fixes">eight security vulnerability fixes</a> some of which will allow code execution. It also includes updates to the H.264 codec, support for full screen viewing and &#8220;numerous bug fixes&#8221;.  The update requires a reboot on both Mac and Windows.</p>
<p>The iTunes update brings iTunes to 7.3.1 and fixes a problem with iTunes 7.3 accessing the library. No other changes are documented.</p>
<p>Both patches are available through Apple software update or from the <a href="http://www.apple.com/support/downloads/" title="Jump to the download page on the Apple website">Apple download</a> page.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/20/apple-tv-security-update/" rel="bookmark" class="crp_title">Apple TV Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yahoo Messenger Critical Security Update</title>
		<link>http://www.spamchronicles.com/2007/06/10/yahoo-messenger-critical-security-update/</link>
		<comments>http://www.spamchronicles.com/2007/06/10/yahoo-messenger-critical-security-update/#comments</comments>
		<pubDate>Sun, 10 Jun 2007 15:51:36 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[software-security-patch]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/yahoo-messenger-critical-security-update/</guid>
		<description><![CDATA[Yahoo has released a new version of Messenger, their instant messaging client. Yahoo&#8217;s bulletin lists the impact as: Some impacts of a buffer overflow might include the introduction of executable code, being involuntarily logged out of a Chat and/or Instant Messaging session, and the crash of an application such as Internet Explorer. For this specific [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Yahoo</strong> has released a new version of <strong>Messenger</strong>, their instant messaging client. <a href="http://messenger.yahoo.com/security_update.php?id=060707" title="Jump to the Yahoo security bulletin">Yahoo&#8217;s bulletin</a> lists the impact as:</p>
<blockquote><p>Some impacts of a buffer overflow might include the introduction of executable code, being involuntarily logged out of a Chat and/or Instant Messaging session, and the crash of an application such as Internet Explorer. For this specific security issue, these impacts could only be possible if an attacker is successful in prompting someone to view malicious HTML code, most likely executed by getting a person to visit their web page.</p></blockquote>
<p>The vulnerability exists in any Windows version of Messenger that was downloaded before June 8th. The vulnerability exists in the Windows version only. Mac, Mobile and Unix versions of Messenger are not affected. To update you need to download and run the <a href="http://messenger.yahoo.com/webmessengerpromo.php" title="Jump to the Yahoo Messenger page">full Messenger installation</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2006/12/23/aolyahoogmail-spam-filters/" rel="bookmark" class="crp_title">AOL/Yahoo/GMail Spam Filters</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/10/yahoo-messenger-critical-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.4 &#8211; Security Update</title>
		<link>http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/</link>
		<comments>http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/#comments</comments>
		<pubDate>Thu, 31 May 2007 15:11:51 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/firefox-2004-security-update/</guid>
		<description><![CDATA[Firefox has released an update with six vulnerability fixes for Firefox 2 which ups the version number to 2.0.0.4 One of the fixes is listed as &#8220;critical&#8221;. There&#8217;s also numerous other updates and bug fixes. Enhancements include &#8220;enchancements and fixes for Windows Vista&#8221; and support for two new languages &#8211; Afrikaans (af) and Belarusian (be). [...]]]></description>
			<content:encoded><![CDATA[<p>Firefox has released an update with <a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.4" title="Jump to the list of vulnerability fixes">six vulnerability fixes</a> for Firefox 2 which ups the version number to 2.0.0.4 One of the fixes is listed as &#8220;critical&#8221;. There&#8217;s also numerous other <a href="http://forums.mozillazine.org/viewtopic.php?p=2866044" title="Jump to the Wiki that lists the bug fixes">updates and bug fixes.</a></p>
<p>Enhancements include &#8220;enchancements and fixes for Windows Vista&#8221; and support for two new languages &#8211; Afrikaans (af) and Belarusian (be).</p>
<p>Beginning with version 2.0.0.3 there was a problem with the Java Console which is <a href="http://kb.mozillazine.org/Firefox_:_FAQs_:_Install_Java" title="Jump to the the Mozilla KB about the Java console">documented by Mozilla</a>, this also exists with this update.</p>
<blockquote><p>The Sun JRE installs a Java console extension in the program directory, which is not visible in Tools -&gt; Add-ons. JRE 6 is not compatible with Firefox 2.0.0.3 due to the manifest file setting the maximum version number to 2.0.0.0. This causes a message about the Java console being disabled when you upgrade to Firefox 2.0.0.3. If you change that number to 2.0.0.* configure the Java control panel to show the Java console and run a Java applet, sometimes the console will work, other times it will hang Firefox (so it seems to be more than just a version check problem)</p>
</blockquote>
<p>You&#8217;ll probably receive a warning that this add-on isn&#8217;t compatible when you install this update. If you need the java console refer to the FAQ for alternatives.</p>
<p>The update is available through Firefox&#8217;s built-in update function or you can <a href="http://www.mozilla.com/firefox/all.html" title="Jump to the Mozilla download page">download it from Mozilla</a>.</p>
<p>Firefox 1.5 was also updated to Firefox 1.5.0.12 and includes similar updates. Mozilla has stated they intend this to be the last update to the 1.5 branch of their product.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quicktime Security Update</title>
		<link>http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/</link>
		<comments>http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/#comments</comments>
		<pubDate>Wed, 30 May 2007 12:54:31 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[itunes]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[software-security-patch]]></category>
		<category><![CDATA[software-upgrade]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/quicktime-security-update/</guid>
		<description><![CDATA[Apple has release a security update for Quicktime. The update is for Quicktime on both Windows and OS X. The update patches two vulnerabilities that can be triggered by visiting a malicious website. The first allows code to be executed, the second could allow the &#34;disclosure of senesitive information&#34;. Apple has also released an update [...]]]></description>
			<content:encoded><![CDATA[<p>Apple has release a <a href="http://docs.info.apple.com/article.html?artnum=305531" title="Jump to the Apple bulletin on the update.">security update for Quicktime</a>. The update is for <strong>Quicktime</strong> on both <strong>Windows</strong> and <strong>OS X</strong>. The update patches two vulnerabilities that can be triggered by visiting a malicious website. The first allows code to be executed, the second could allow the &quot;disclosure of senesitive information&quot;.</p>
<p>Apple has also released an <a href="http://www.apple.com/support/downloads/itunes72formac.html" title="Jump to the Apple update notification">update to iTunes</a> that now includes support for DRM free music. This update doesn&#8217;t have any security implications.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/20/apple-tv-security-update/" rel="bookmark" class="crp_title">Apple TV Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
