<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; security vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/security-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Mon, 09 Nov 2009 23:09:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Adobe Fixes Critical Shockwave Vulnerability</title>
		<link>http://www.ghacks.net/2009/06/25/adobe-fixes-critical-shockwave-vulnerability/</link>
		<comments>http://www.ghacks.net/2009/06/25/adobe-fixes-critical-shockwave-vulnerability/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 06:51:09 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe shockwave]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[shockwave]]></category>
		<category><![CDATA[shockwave update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=13844</guid>
		<description><![CDATA[Adobe has issues a security patch for their Adobe Shockwave software program that fixes on vulnerability that has been rated critical. The vulnerability gives attackers, who can attack systems remotely, control over affected computer systems. The interesting aspect of the issued patch is that Adobe recommends to completely uninstall Adobe Shockwave 11.5.0.596 or earlier on [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/06/adobe_shockwave.jpg" alt="adobe shockwave" title="adobe shockwave" width="100" height="100" class="alignleft size-full wp-image-13845" />Adobe has issues a security patch for their Adobe Shockwave software program that fixes on vulnerability that has been rated critical. The vulnerability gives attackers, who can attack systems remotely, control over affected computer systems. The interesting aspect of the issued patch is that Adobe recommends to completely uninstall Adobe Shockwave 11.5.0.596 or earlier on their computer systems before installing the latest version of the software product in which the security vulnerability has been fixed.</p>
<p>To secure a computer system running Adobe Shockwave a user would therefor have to uninstall Adobe Shockwave, perform a system restart and install the latest version of Shockwave after the reboot.</p>
<p><span id="more-13844"></span>The Security Bulletin that has been published at the Adobe website gives little information about the vulnerability other than it can be remotely exploited and that it only affects the Microsoft Windows operating system. Users are encouraged to download the latest version of Adobe Shockwave on the <a href="http://get.adobe.com/shockwave/">program&#8217;s</a> website.</p>
<p>It should also be noted that this vulnerability targets only Adobe Shockwave and not Adobe Flash. Thanks goes to Dante for sending me the information per email.</p>

	Tags: <a href="http://www.ghacks.net/tag/adobe/" title="adobe" rel="tag">adobe</a>, <a href="http://www.ghacks.net/tag/adobe-flash/" title="adobe flash" rel="tag">adobe flash</a>, <a href="http://www.ghacks.net/tag/adobe-shockwave/" title="adobe shockwave" rel="tag">adobe shockwave</a>, <a href="http://www.ghacks.net/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a>, <a href="http://www.ghacks.net/tag/shockwave/" title="shockwave" rel="tag">shockwave</a>, <a href="http://www.ghacks.net/tag/shockwave-update/" title="shockwave update" rel="tag">shockwave update</a>, <a href="http://www.ghacks.net/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/12/08/game-for-the-weekend-3-isketch/" title="Game for the Weekend 3 iSketch (December 8, 2006)">Game for the Weekend 3 iSketch</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/10/08/adobe-flash-player-clickjacking-vulnerability/" title="Adobe Flash Player Clickjacking Vulnerability (October 8, 2008)">Adobe Flash Player Clickjacking Vulnerability</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/09/06/youd-be-stupid-not-to/" title="You&rsquo;d be Stupid Not To&hellip; (September 6, 2008)">You&rsquo;d be Stupid Not To&hellip;</a> (31)</li>
	<li><a href="http://www.ghacks.net/2008/06/27/you-better-stop-using-internet-explorer-for-now/" title="You better stop using Internet Explorer for now (June 27, 2008)">You better stop using Internet Explorer for now</a> (18)</li>
	<li><a href="http://www.ghacks.net/2008/05/28/vulnerabilities-in-latest-flash-version/" title="Vulnerabilities in latest Flash version (May 28, 2008)">Vulnerabilities in latest Flash version</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/06/25/adobe-fixes-critical-shockwave-vulnerability/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Bulletin May 2009</title>
		<link>http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/</link>
		<comments>http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/#comments</comments>
		<pubDate>Wed, 13 May 2009 14:05:31 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft security bulleting]]></category>
		<category><![CDATA[microsoft-office]]></category>
		<category><![CDATA[security bulletin]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[windows updates]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/</guid>
		<description><![CDATA[Microsoft has released the Security Bulletin for May 2009 which contains one Microsoft Office PowerPoint vulnerability which affects various editions of Microsoft Office but also the Microsoft Office PowerPoint Viewer and Microsoft Office Compatibility Pack. Affected are Microsoft Office PowerPoint editions in Microsoft Office 2000, Office XP, Office 2003 and Microsoft Office 2007. The security [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_office.jpg" alt="microsoft office" title="microsoft office" width="128" height="105" class="alignleft size-full wp-image-12120" />Microsoft has released the Security Bulletin for May 2009 which contains one Microsoft Office PowerPoint vulnerability which affects various editions of Microsoft Office but also the Microsoft Office PowerPoint Viewer and Microsoft Office Compatibility Pack. Affected are Microsoft Office PowerPoint editions in Microsoft Office 2000, Office XP, Office 2003 and Microsoft Office 2007. The security update is rated as critical for Microsoft Office 2000 editions and important for all other affected editions of Microsoft Office and software programs by Microsoft.</p>
<p><span id="more-12792"></span><br />
<blockquote>This security update resolves a publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p></blockquote>
<p>The security update is available on Windows Update and Microsoft Update. Additional information and links can be found at the <a href="http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx">Security Bulletin</a> that has been created for the security vulnerability. Users of affected software programs are encouraged to perform the security update as soon as possible.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-security-bulleting/" title="microsoft security bulleting" rel="tag">microsoft security bulleting</a>, <a href="http://www.ghacks.net/tag/microsoft-office/" title="microsoft-office" rel="tag">microsoft-office</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-bulletin/" title="security bulletin" rel="tag">security bulletin</a>, <a href="http://www.ghacks.net/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a>, <a href="http://www.ghacks.net/tag/windows-updates/" title="windows updates" rel="tag">windows updates</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/03/10/microsoft-patch-day-march-2009/" title="Microsoft Patch Day March 2009 (March 10, 2009)">Microsoft Patch Day March 2009</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/08/13/microsoft-august-2008-security-updates/" title="Microsoft August 2008 Security Updates (August 13, 2008)">Microsoft August 2008 Security Updates</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/" title="Game Over For Windows Vista&#8217;s Security? (August 8, 2008)">Game Over For Windows Vista&#8217;s Security?</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/02/27/february-2008-security-releases-iso-image/" title="February 2008 Security Releases ISO Image (February 27, 2008)">February 2008 Security Releases ISO Image</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/05/13/microsoft-security-bulletin-may-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Chrome Security Vulnerability</title>
		<link>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/</link>
		<comments>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 21:41:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[google browser]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[google chrome security vulnerability]]></category>
		<category><![CDATA[google chrome vulnerability]]></category>
		<category><![CDATA[google security]]></category>
		<category><![CDATA[security vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6748</guid>
		<description><![CDATA[Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky discovered (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in [...]]]></description>
			<content:encoded><![CDATA[<p>Now this did not take long. Only one day after releasing a first public beta version of Google Chrome researchers at Kaspersky <a href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php">discovered</a> (Thanks Neil for sending the tip) a security vulnerability that combines a security flaw in Webkit, the browser engine used by Google Chrome, with a Java bug. Apple fixed the vulnerability in Safari back in July after two months of doing nothing about it and it will be interesting to see how fast Google will react to the security vulnerability.</p>
<p>The reason why this vulnerability is still working in Google Chrome is because Google has been using an older version of Webkit for their browser&#8217;s core. First of all, users without Java on their computers are completely safe. Users with Java and Chrome installed should read on.</p>
<p>The problem is serious but requires the user&#8217;s action to be triggered. If the user clicks on a specifically prepared download the file downloads and executes itself automatically without further user input.</p>
<p><span id="more-6748"></span>Security expert Aviv Raff has setup a demo website that demonstrates the vulnerability in Google Chrome. The demonstration page provides a download button which will download and execute a Java file immediately without further user interaction. This demo only opens a notepad application but serious harm could be done with such an exploit.</p>

	Tags: <a href="http://www.ghacks.net/tag/google-browser/" title="google browser" rel="tag">google browser</a>, <a href="http://www.ghacks.net/tag/google-chrome/" title="google chrome" rel="tag">google chrome</a>, <a href="http://www.ghacks.net/tag/google-chrome-security-vulnerability/" title="google chrome security vulnerability" rel="tag">google chrome security vulnerability</a>, <a href="http://www.ghacks.net/tag/google-chrome-vulnerability/" title="google chrome vulnerability" rel="tag">google chrome vulnerability</a>, <a href="http://www.ghacks.net/tag/google-security/" title="google security" rel="tag">google security</a>, <a href="http://www.ghacks.net/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/10/why-google-chrome-os-will-have-no-huge-impact/" title="Why Google Chrome OS Will Have No Huge Impact (July 10, 2009)">Why Google Chrome OS Will Have No Huge Impact</a> (20)</li>
	<li><a href="http://www.ghacks.net/2009/09/23/who-the-hell-needs-google-chrome-frame/" title="Who The Hell Needs Google Chrome Frame? (September 23, 2009)">Who The Hell Needs Google Chrome Frame?</a> (11)</li>
	<li><a href="http://www.ghacks.net/2009/06/21/web-browser-memory-usage-benchmark-gets-it-all-wrong/" title="Web Browser Memory Usage Benchmark Gets It All Wrong (June 21, 2009)">Web Browser Memory Usage Benchmark Gets It All Wrong</a> (15)</li>
	<li><a href="http://www.ghacks.net/2009/10/17/ten-great-google-chrome-themes/" title="Ten Great Google Chrome Themes (October 17, 2009)">Ten Great Google Chrome Themes</a> (16)</li>
	<li><a href="http://www.ghacks.net/2009/08/23/sync-google-chrome-bookmarks-with-xmarks/" title="Sync Google Chrome Bookmarks With Xmarks (August 23, 2009)">Sync Google Chrome Bookmarks With Xmarks</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/09/03/google-chrome-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>Game Over For Windows Vista&#8217;s Security?</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/</link>
		<comments>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 12:44:57 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[vista security]]></category>
		<category><![CDATA[windows-vista]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=5968</guid>
		<description><![CDATA[I picked up an interesting story over at Neowin entitled &#8220;Vista&#8217;s Security Rendered Completely Useless by New Exploit&#8221; which reports on a new technique hat can &#8220;bypass all memory protection safeguards that Microsoft built into Windows Vista.&#8221;
The researchers were able to load whatever content they wanted into any location they wished on a user&#8217;s machine [...]]]></description>
			<content:encoded><![CDATA[<p>I picked up an interesting story over at <a href="http://www.neowin.net/news/main/08/08/08/vista39s-security-rendered-completely-useless-by-new-exploit">Neowin</a> entitled &#8220;Vista&#8217;s Security Rendered Completely Useless by New Exploit&#8221; which reports on a new technique hat can &#8220;bypass <strong>all</strong> memory protection safeguards that Microsoft built into Windows Vista.&#8221;</p>
<p><strong>The researchers were able to load whatever content they wanted into any location they wished on a user&#8217;s machine using a variety of scripting languages, such as Java, ActiveX and even .NET objects. This feat was achieved by taking advantage of the way that <a href="http://www.ghacks.net/tag/internet-explorer/">Internet Explorer</a> (and other browsers) handle active scripting in the Operating System.</strong></p>
<p>Instead of exploiting a security vulnerability the researchers Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. of the architecture of Windows Vista. Another researcher described the technique as &#8220;completely game over.&#8221;</p>
<p><span id="more-5968"></span>It&#8217;s currently not known if other operating systems are vulnerable as well but it is very likely. The best against this attack would be an add-on like NoScript that would most likely prevent it completely.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a>, <a href="http://www.ghacks.net/tag/vista-security/" title="vista security" rel="tag">vista security</a>, <a href="http://www.ghacks.net/tag/windows-vista/" title="windows-vista" rel="tag">windows-vista</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/03/30/windows-integrity-levels/" title="Windows Integrity Levels for extra security in Windows Vista (March 30, 2008)">Windows Integrity Levels for extra security in Windows Vista</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/04/23/yuck-new-windows-vista-ultimate-extras/" title="Yuck new Windows Vista Ultimate Extras (April 23, 2008)">Yuck new Windows Vista Ultimate Extras</a> (20)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/xp-sp3-and-vista-sp-1-available-through-windows-update/" title="XP SP3 and Vista SP 1 available through Windows Update (May 7, 2008)">XP SP3 and Vista SP 1 available through Windows Update</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/08/26/windows-xp-wga-to-mimic-that-of-windows-vista/" title="Windows XP WGA To Mimic That Of Windows Vista (August 26, 2008)">Windows XP WGA To Mimic That Of Windows Vista</a> (18)</li>
	<li><a href="http://www.ghacks.net/2006/05/19/windows-vista-upgrade-advisor/" title="Windows Vista Upgrade Advisor (May 19, 2006)">Windows Vista Upgrade Advisor</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>
