<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; security update</title> <atom:link href="http://www.ghacks.net/tag/security-update/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Flash Player, VLC Security Updates Released</title><link>http://www.ghacks.net/2011/06/06/flash-player-vlc-security-updates-released/</link> <comments>http://www.ghacks.net/2011/06/06/flash-player-vlc-security-updates-released/#comments</comments> <pubDate>Mon, 06 Jun 2011 13:03:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash update]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[vlc]]></category> <category><![CDATA[vlc media player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46129</guid> <description><![CDATA[Adobe and VideoLAN have released security updates for some of their software programs today. Adobe released a new version of Adobe Flash Player which fixes a security vulnerability in the popular application. The security bulletin reveals that an important security vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier on all supported operating [...]]]></description> <content:encoded><![CDATA[<p>Adobe and VideoLAN have released security updates for some of their software programs today. Adobe released a new version of Adobe Flash Player which fixes a security vulnerability in the popular application. The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-13.html">reveals</a> that an important security vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier on all supported operating systems including Flash on Android. The cross-site scripting vulnerability could be used to impersonate a user on a website such as that of a webmail provider or financial website. Adobe confirmed reports that the vulnerability is actively exploited by embedded malicious links in email messages.</p><p>The update is classified as important which is the second highest severity rating available.</p><p>Flash users can verify the installed version of the application <a
href="http://www.adobe.com/products/flash/about/">by visiting</a> Adobe&#8217;s Flash Player page. The system is vulnerable to the attacks if the Flash version is 10.3.181.16 or earlier.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/flash-player-version-check.png" alt="flash player version check" title="flash player version check" width="600" height="447" class="alignnone size-full wp-image-46130" /></p><p>Download links are provided on the security bulletin&#8217;s page. The latest version can be downloaded from the official <a
href="http://get.adobe.com/flashplayer/">Get Flash Player</a> page as well. <a
href="http://www.ghacks.net/2011/05/13/adobe-flash-player-10-3-final-downloads/">Direct Downloads</a> are available as well.</p><p>Adobe is currently not aware of attacks that use the authplay.dll component that ships with Adobe Reader and Acrobat. While the company is not aware of attacks at this point in time, it has not completed the investigation if authplay.dll is vulnerable to the recently discovered Flash vulnerability.</p><p><strong>In other news: </strong>The developers of the popular video player VLC have also released a new version of their application to protect users from recently discovered security issues.</p><p>The <a
href="http://www.videolan.org/vlc/releases/1.1.10.html">release notes</a> list an integer overflow vulnerability in xspf demuxer as well as several updates and rewrites of features in the latest version of the media player.</p><p>VLC users are encouraged to download and install the latest version of the player right away to protect their system from possible exploits.</p><p>Downloads are as <a
href="http://www.videolan.org/vlc/releases/1.1.10.html">usually</a> offered at the official Videolan website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/06/flash-player-vlc-security-updates-released/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>WordPress 3.1.2 Released, Security Update</title><link>http://www.ghacks.net/2011/04/26/wordpress-3-1-2-released-security-update/</link> <comments>http://www.ghacks.net/2011/04/26/wordpress-3-1-2-released-security-update/#comments</comments> <pubDate>Tue, 26 Apr 2011 20:48:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Web Development]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=44411</guid> <description><![CDATA[WordPress has just released a new version of the popular blogging platform. WordPress 3.1.2 is a security update which makes it a mandatory update for all self-hosted WordPress sites. The update &#8220;addresses a vulnerability that allowed Contributor-level users to improperly publish posts&#8221; notes Ryan Boren at the official WordPress blog. The WordPress developers suggest to [...]]]></description> <content:encoded><![CDATA[<p>WordPress has just released a new version of the popular blogging platform. WordPress 3.1.2 is a security update which makes it a mandatory update for all self-hosted WordPress sites. The update &#8220;addresses a vulnerability that allowed Contributor-level users to improperly publish posts&#8221; <a
href="http://wordpress.org/news/2011/04/wordpress-3-1-2/">notes</a> Ryan Boren at the official WordPress blog.</p><p>The WordPress developers suggest to update immediately, especially if users can register as contributors on the blog. WordPress 3.1.2 fixes several non-security related issues which you can see a list of at the <a
href="http://core.trac.wordpress.org/query?milestone=3.1.2">issue tracker</a> over at the WordPress website.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/wordpress-update1-570x203.png" alt="wordpress update" title="wordpress update" width="570" height="203" class="alignnone size-medium wp-image-44412" /></p><p>Nothing to spectacular fixed though, take a look below for the list.</p><ul><li>It&#8217;s tricky to drag metaboxes</li><li>Apostrophe in first/last/nickname causes JS error on user profile page</li><li>Missing closing &lt;/fieldset&gt; in user-edit.php for &#8220;show admin bar&#8221;</li><li>Multiple tag queries broken</li><li>WP_User_Query ordered by post_count doesn&#8217;t work if prefix is not wp_</li><li>WordPress 3.1.1 breaks date archive filtering by tag or category</li><li>Walker_PageDropdown doesn&#8217;t filter titles correctly</li><li>Too much escaping for pages when using Quick Edit</li></ul><p>WordPress administrators can update their blogs either directly from the WordPress Dashboard with a click on the Update Automatically button, or by downloading the new release <a
href="http://wordpress.org/download/">from the</a> official WordPress website, uploading the files manually to the server and running the upgrade script afterwards.</p><p>I have just updated more than a dozen WordPress blog to version 3.1.2 and the automatic update worked without difficulties in every instance. WordPress admins should not encounter any page display problems on the frontend or backend after applying the update.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/26/wordpress-3-1-2-released-security-update/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>VLC Media Player Security Update</title><link>http://www.ghacks.net/2011/04/13/vlc-media-player-security-update/</link> <comments>http://www.ghacks.net/2011/04/13/vlc-media-player-security-update/#comments</comments> <pubDate>Wed, 13 Apr 2011 14:15:24 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[media-player]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[videolan]]></category> <category><![CDATA[vlc]]></category> <category><![CDATA[vlc media player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43869</guid> <description><![CDATA[VLC Media Player is one of the most popular media players, next to Windows Media Player and MPlayer frontends. A high popularity usually has the downside that criminals try to find and exploit security vulnerabilities in the software or service. Several of the most recent updates of VLC were or did include security updates that [...]]]></description> <content:encoded><![CDATA[<p>VLC Media Player is one of the most popular media players, next to Windows Media Player and MPlayer frontends. A high popularity usually has the downside that criminals try to find and exploit security vulnerabilities in the software or service. Several of the most recent updates of VLC were or did include security updates that fixed previously discovered security vulnerability in the application.</p><p>The developers of VLC have released a new version of the program yesterday that patches another security vulnerability in the program.</p><p>It took the VLC team less than five days to fix the vulnerability which was first disclosed on April 7. The security advisory on the <a
href="http://www.videolan.org/security/sa1103.html">Videolan</a> web page describes the issue as a heap-based buffer overflow in the mp4 demuxer.</p><p>Workarounds have been posted on the very same page, which are however no longer necessary as the issue is fixed by the VLC update to version 1.1.9.</p><p>The built-in update checker does not seem to recognize the new update yet, which means that VLC users need to download the update from the homepage of the project to install the program update manually. Downloads for all supported operating systems are available <a
href="http://www.videolan.org/vlc/">on this</a> page.</p><p>You can verify the version of VLC by clicking on Help > About in the program interface, or with the keyboard shortcut Shift-F1.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/vlc-update.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/vlc-update.png" alt="vlc update" title="vlc update" width="307" height="179" class="alignnone size-full wp-image-43871" /></a></p><p>If you see VLC Media Player 1.1.8 there you need to update the software. Manual update checks are available via Help > Check for Updates. It is likely that the developers will enable automatic updates soon.</p><p>VLC 1.1.9 includes an update for the libmodplug which is security related as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/13/vlc-media-player-security-update/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft Updates Windows To Block Fraudulent Digital Certificates</title><link>http://www.ghacks.net/2011/03/25/microsoft-updates-windows-to-block-fraudulent-digital-certificates/</link> <comments>http://www.ghacks.net/2011/03/25/microsoft-updates-windows-to-block-fraudulent-digital-certificates/#comments</comments> <pubDate>Fri, 25 Mar 2011 09:55:20 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43046</guid> <description><![CDATA[If you follow this blog closely you may have noticed that several browser developers have pushed security updates in the past week (see Mozilla Releases Firefox 3 Security Updates for instance) that block several invalid digital certificates to protect users from attacks exploiting those certificates. Microsoft is currently pushing out a Windows Update that addresses [...]]]></description> <content:encoded><![CDATA[<p>If you follow this blog closely you may have noticed that several browser developers have pushed security updates in the past week (see <a
href="http://www.ghacks.net/2011/03/23/mozilla-releases-firefox-3-security-updates/">Mozilla Releases Firefox 3 Security Updates</a> for instance) that block several invalid digital certificates to protect users from attacks exploiting those certificates.</p><p>Microsoft is currently pushing out a Windows Update that addresses the situation on Windows. Lets take a closer look at what actually happened before we go into details about that.</p><p>Comodo, a certification authority, notified Microsoft and other companies on March 16 that &#8220;nine certificates had been signed on behalf of a third party without sufficiently validating its identity&#8221;.</p><p>The following domains are affected by the certificates:</p><ul><li>login.live.com</li><li>mail.google.com</li><li>www.google.com</li><li>login.yahoo.com</li><li>login.skype.com</li><li>addons.mozilla.org</li><li>Global Trustee</li></ul><p>These domains are some of the most visited domains on the Internet.</p><p>Microsoft notes that &#8220;these certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer&#8221;.</p><p>Comodo has revoked the certificates in the meantime. Microsoft has released a security update for all versions of Windows that moves the fraudulent certificates into the untrusted certificate store of Microsoft Windows.</p><p>The update is provided via Windows Update and Microsoft Download. Users with automatic updating enabled will receive the update automatically, a restart of the system is not required after the update has been installed.</p><ul><li>Microsoft Security Advisory: Fraudulent Digital Certificates could allow spoofing at Microsoft Download [<a
href="http://support.microsoft.com/kb/2524375">link</a>] for direct downloading.</li><li>Security Advisory [<a
href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">link</a>]</li></ul><p>Here is how you can verify that the certificates are blocked after you have installed the update. Open an elevated command prompt. Windows 7 users click on <strong>Start</strong>, select <strong>All Programs > Accessories</strong>, right-click the <strong>Command Prompt</strong> program link and select <strong>Run as Administrator</strong>.</p><p>Enter <strong>mmc</strong> in the command prompt window to launch the Microsoft Management Console. Now follow these steps:</p><ul><li>Press Ctrl-m or select File > Add / Remove Snap In</li><li>Find Certificates in the listing, select it with a left-click and click on Add.</li></ul><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/windows-certificates-550x387.png" alt="windows certificates" title="windows certificates" width="550" height="387" class="alignnone size-medium wp-image-43047" /></p><ul><li>Select Computer Account on the next window and press Finish</li><li>Click the ok button to leave the Add or Remove Snap-ins configuration window.</li><li>Expand the certificates listing under Console Root and then the Untrusted Certificates sub-listing. Click on the Certificates folder there.</li></ul><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/untrusted-certificates-550x313.png" alt="untrusted certificates" title="untrusted certificates" width="550" height="313" class="alignnone size-medium wp-image-43048" /></p><p>You should now see the affected domain names in the listing. Issued by should read UTN-USERFirst-Hardware.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/25/microsoft-updates-windows-to-block-fraudulent-digital-certificates/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Assess Windows Security State With Microsoft Baseline Security Analyzer</title><link>http://www.ghacks.net/2009/10/28/assess-windows-security-state-with-microsoft-baseline-security-analyzer/</link> <comments>http://www.ghacks.net/2009/10/28/assess-windows-security-state-with-microsoft-baseline-security-analyzer/#comments</comments> <pubDate>Wed, 28 Oct 2009 17:48:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[Microsoft Baseline Security Analyzer]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[windows software]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17830</guid> <description><![CDATA[Microsoft updated their Microsoft Baselines Security Analyzer software recently to make the software compatible with Windows 7 and Windows Server 2008 R2. The concept of the program remains unchanged: To offer system administrators and end users a comfortable way of assessing the security state of a Windows computer system. Microsoft Baseline Security Analyzer can assess [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/09/windows_software.jpg" alt="windows software" title="windows software" width="128" height="128" class="alignleft size-full wp-image-16120" />Microsoft updated their Microsoft Baselines Security Analyzer software recently to make the software compatible with Windows 7 and Windows Server 2008 R2. The concept of the program remains unchanged: To offer system administrators and end users a comfortable way of assessing the security state of a Windows computer system. Microsoft Baseline Security Analyzer can assess the security state for local and remote computer systems.</p><p>System administrators can select a known computer name or enter an IP address and port during configuration of the analyzer. It is furthermore possible to select the multi-scan option which allows the admin to specify an IP range for the scan. Various options are provided in the configuration menu that basically configure the depth of the scan. It will by default check for Windows administrative vulnerabilities, weak passwords, IIS administrative vulnerabilities, SQL administrative vulnerability and security updated with addition options selectable for advanced usage.</p><p><span
id="more-17830"></span><img
src="http://www.ghacks.net/wp-content/uploads/2009/10/microsoft_baseline_security_analyzer1-500x375.jpg" alt="microsoft baseline security analyzer" title="microsoft baseline security analyzer" width="500" height="375" class="alignnone size-medium wp-image-17842" /></p><p>The security assessment report will then display if security risks have been found during the scan. These risks will be displayed in an overview at the top of the report which gives an option to quickly look over the findings of the software program. Each section outlines what the program scanned, gives details about the results and offers solutions to correct the issues that were found.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2009/10/security_scan-500x257.jpg" alt="security scan" title="security scan" width="500" height="257" class="alignnone size-medium wp-image-17843" /></p><p>To give one basic example. If the program finds that security updates are missing it will display those missing updates with options to download them right away. Microsoft Baseline Security Analyzer is a free download for all Microsoft operating systems since Windows 2000 including Windows XP, Windows Vista and Windows 7. The program is <a
href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=b1e76bbe-71df-41e8-8b52-c871d012ba78&amp;displaylang=en">available</a> for 32-bit and 64-bit editions.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/28/assess-windows-security-state-with-microsoft-baseline-security-analyzer/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Opera 9.62 Security Update</title><link>http://www.ghacks.net/2008/11/24/opera-962-security-update/</link> <comments>http://www.ghacks.net/2008/11/24/opera-962-security-update/#comments</comments> <pubDate>Sun, 23 Nov 2008 22:52:28 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Opera]]></category> <category><![CDATA[opera browser]]></category> <category><![CDATA[opera market share]]></category> <category><![CDATA[opera presto]]></category> <category><![CDATA[opera security]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[web browser]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8490</guid> <description><![CDATA[A new version of the excellent web browser Opera has been released today. The browser which many Opera users consider superior to the other major browsers is stuck at about 2% market share which is slowly on the rise according to the Browser Statistics published by W3Schools. The new version of Opera is a recommended [...]]]></description> <content:encoded><![CDATA[<p>A new version of the excellent web browser Opera has been released today. The browser which many Opera users consider superior to the other major browsers is stuck at about 2% market share which is slowly on the rise according to the Browser Statistics published by <a
href="http://www.w3schools.com/browsers/browsers_stats.asp">W3Schools</a>.</p><p>The new version of Opera is a recommended security upgrade which fixes two security issues. The first fixes an issue where History Search could be used to execute arbitrary code while the second ensures that the links panel no longer allows cross-site scripting. The only other addition is the incorporation of the Opera Presto 2.1.1 user agent engine.</p><p><a
href="http://www.opera.com/browser/">Opera</a> users should upgrade the browser as soon as possible to secure the browser from those reported vulnerabilities.</p><p><span
id="more-8490"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/11/24/opera-962-security-update/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
