Showing posts with label Patch. Show all posts
Showing posts with label Patch. Show all posts

Friday, 23 August 2013

Xerox releases patch for scanning error issue


Xerox has issued the first software patch intended to fix a problem in some multi-function printers that causes characters to be incorrectly reproduced when scanned.

The problem first came to light in early August when a German computer scientist noticed errors in the reproduction of a building floor plan. Examining a PDF document of the scanned plan, he noticed some figures printed in a small, fine font on a document were incorrectly copied.

“We have confirmed that errors can occur under a set of limited conditions when scanning ‘stress documents’ to PDF—which can include very small font sizes, stray pixels and be difficult to read. Given this finding, however uncommon, we have developed this patch which eliminates that possibility,” the company said in a statement.

Xerox said the problem only occurs with such “stress documents,” which it defines as those that have “small fonts, are hard to read, contain stray pixels and/or have been scanned multiple times.”

Arcsoft Print Creation offers A family of fun and easy print projectsThe problem doesn’t occur when documents are printed, copied or sent via fax.

“Our engineering team has been working around the clock to deliver the patch. We have conducted extensive testing both in our labs and in the field to assure a quality result and an easy installation,” Xerox said.

The first patch is for the Xerox ConnectKey family, WorkCentre 75xx, WorkCentre 57xx and ColorQube 93xx machines. A second patch will be available next week that covers the rest of the affected products.

“I want to thank all of our customers, agents and partners around the world for working with us and providing feedback throughout this process,” Rick Dastin, president of the Xerox Office and Solutions Business Group, said in a statement. 

Friday, 19 July 2013

Remote access a priority for latest Oracle patch update

The vulnerabilities that allow for remote unauthenticated access should be a priority for administrators applying the latest Oracle Critical Patch Update (CPU) say security experts.
This means businesses will need to focus on applying more than 40% of the 89 updates that cover most of Oracle’s product groups.
Java is on a different update cycle of every four months, but it will be migrated to the same schedule from October 2013. 
Oracle’s flagship product, the Oracle database, gets six updates this month, with four being remotely exploitable.
The XML parser vulnerability, which is remotely accessible but requires authentication, has the highest Common Vulnerability Scoring System (CVSS) score of the Critical Patch Update, scoring nine on a scale of 10, indicating high criticality.

“One mitigating factor is that Oracle databases are typically not exposed the internet,” said Wolfgang Kandek, chief technology officer at security firm Qualys.

Oracle’s MySQL database has 18 vulnerabilities addressed, including two that are remotely accessible and have a CVSS score of 6.8.

“MySQL is often found exposed to the internet, even though this is not considered best practice. If you use MySQL in your organisation, it makes sense to run a perimeter scan to collect information on all databases externally exposed,” said Kandek.

The Oracle Sun product line has 16 updates, with eight being remotely accessible. The highest CVSS score is 7.8.

“If you have Sun Solaris servers in your organisation, review these patches and start with the machines on your perimeter and DMZ,” said Kandek.

Oracle’s Fusion Middleware has a total of 21 vulnerabilities and includes many components that are typically found on the internet, such as the Oracle HTTP server.
Of the 21 vulnerabilities, 16 are accessible remotely, with a maximum CVSS score of 7.5. “Again, a perimeter scan is helpful, or even a quick query to Shodan, which shows more than 500,000 machines with Oracle’s HTTP out on the internet,” said Kandek.

The highest CVSS score is 7.5, which should not be ignored, said Ross Barrett, senior manager of security engineering at Rapid7.

Fusion contains the Outside-In product that is used in Microsoft Exchange for document viewing. Outside-In has, in the past year, caused two updates in Microsoft’s email product to address the vulnerabilities in MS12-058 and MS12-080.

According to Kandek, recent research by Will Domann shows that Outside-In has the potential for more vulnerabilities. He recommends turning off the WebReady feature, which means that users have to download the documents to the local disk for viewing.

Other product areas with security updates include Peoplesoft, E-Business, Virtualisation and Solaris, which has been hit with two remote denial of service (DoS) attacks, plus a couple of local elevation of privilege issues, said Barrett.

This free Computer Weekly special report on Oracle gives an independent view of the challenges facing Oracle, its financial performance, the services it offers, its place in the IT market and its future strategy.
“With such a diverse range of products in this quarter’s patch, it's hard to tackle these from top to bottom. I recommend patching any vulnerable Oracle Database Server instances as soon as possible, and don’t neglect the stability or integrity of the Solaris deployment,” he said.

Kandek said dealing with the large sizes of the Oracle CPUs would be easier if a good map of the currently installed software exists.

“In any case, we recommend addressing vulnerabilities on systems that are internet accessible first, such as Fusion Middleware, the Solaris operating system and MySQL,” he said.

According to Craig Young, a security researcher at Tripwire, Oracle has acknowledged and fixed 343 security issues so far this year.

“In case there was any doubt, this should be a big red flag to users that Oracle’s security practices are simply not working,” he said. “The constant drumbeat of critical Oracle patches is more than a little alarming, particularly because the vulnerabilities are frequently reported by third parties.”

This month’s CPU credits 18 different researchers coming from more than a dozen different companies, he added.

Thursday, 11 July 2013

Patch Tuesday: Malicious fonts bedevil Microsoft Windows

Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

"Fonts have become really complicated," said Wolfgang Kandek, chief technology officer for compliance and security software company Qualys. "There is real processing going on when you print a character, and that complexity can be attacked."

The number of critical bulletins Microsoft released this month is a bit higher than normal, Kandek said. Typically, Microsoft will issue about two or three critical bulletins on Patch Tuesday, which occurs on the second Tuesday of each month. This month half the bulletins -- MS13-052, MS13-053 and MS13-054 -- address how Microsoft systems handle the rendering of TrueType fonts.

With this vulnerability, an attacker can embed malicious values in a font description that would overrun the memory allocated to the font-drawing routine, and write into sections of memory reserved for other operations. The font instructions could be provided to Windows or Internet Explorer (IE) by way of a Web page or a document.

"Depending on where this happens, this can be quite serious," Kandek said.

Windows, for instance, renders all characters onto the screen as a system user, not as a standard user, which has fewer system privileges. An exploit of a font-rendering vulnerability could "go right into the operating system and take control at that level," Kandek said.

Overall, Microsoft issued six critical bulletins, covering Windows OS, the .NET Framework, Silverlight, Office, Visual Studio, Lync and IE. A seventh bulletin, labeled as important, covers the Windows Defender security software.

All six of the critical bulletins include remote code execution vulnerabilities, which can be used to provide attackers with illicit access to machines.

Seventeen of the 34 vulnerabilities covered in the bulletins address IE. "Researchers continue to find flaws in IE, and the attack surface is pretty big," Kandek said, referring to how Microsoft is now supporting five different versions of the browser. The vulnerabilities affect IE versions six through 10 that run on Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows RT.

"The major problem there is that users or companies still maintain old versions of the browser. We would be better off if everyone was on the newer version" of IE, Kandek said.

One Windows vulnerability, which affects memory management, has already been publicly revealed, and has been used for an exploit that can run on the Metasploit penetration testing software. Security researchers are urging administrators to update their own versions of Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 2008, Windows 2012 and Windows RT as soon as possible.

"July is one of the uglier releases we've seen from Microsoft this year. To say that all Microsoft products are affected and everything is affected critically is not an overstatement," wrote Lumension security and forensic analyst Paul Henry in an email statement. "It's difficult to prioritize one or two because all the bulletins likely need your attention this Patch Tuesday."

In addition to Microsoft patches, administrators should also take a look at Adobe's monthly set of patches, also released Tuesday. They cover vulnerabilities in Adobe Flash, Shockwave and ColdFusion, which is server-side software for rendering websites.

Follow me on Twitter @sajilpl

July's Patch Tuesday fixes 6 critical Microsoft flaws

If you use the Windows operating system, or just about any of the core products offered by Microsoft, it's time to install some crucial updates. Today, Microsoft pushed out seven new security bulletins—along with their accompanying patches—as well as a new policy that affects both third-party apps and those developed by Microsoft itself.

Of the seven security bulletins, six of them are rated Critical, while the remaining one is ranked as Important. The Critical security bulletins affect Windows, Internet Explorer, Microsoft Office, Silverlight, and more. The Important security bulletin addresses a privilege elevation flaw in the Windows Defender security software, so that definitely shouldn’t be ignored.
Microsoft squashes a number of bugs
with seven new security bulletins.
Ross Barrett, senior manager of security engineering at Rapid7, stressed this isn't your typical Patch Tuesday announcement. “Basically everything in the core Microsoft world is affected by one or more of these; every supported OS, every version of MS Office, Lync, Silverlight, Visual Studio and .NET. It’s going to be a busy time for security teams everywhere.”

Tyler Reguly, technical manager of security research and development at Tripwire, said it can be difficult to prioritize patch deployment when almost all of them are Critical. “Luckily, there's safety in the known, so customers should patch Internet Explorer first, a common theme for Microsoft patch drops.”

That means start with MS13-055—the ever-popular cumulative patch update for the Internet Explorer web browser. Reguly feels that MS13-053 should be next in line for attention after MS13-055 because it fixes a vulnerability that is already being exploited in the wild.

Qualys CTO Wolfgang Kandek agrees that MS13-053 and MS13-055 are the top priorities, but in his mind the urgency is flip-flopped. In a blog post, Kandek believes that MS13-053 is the most crucial because it affects all versions of the Windows OS, and addresses vulnerabilities that are being actively exploited. Kandek warns, “The most likely attack vector is through end users browsing a malicious web page or opening an infected document, which results in Remote Code Execution that gives control of the affected machine to the attacker.”
Developers--including Microsoft--will have only 180 days to address critical vulnerabilities.
The other big news from Microsoft is the unveiling of a new policy that places a countdown clock on dealing with vulnerabilities. Craig Young, Tripwire security researcher, explained, “Under the new policy, any app in any of the four [Microsoft] app stores will be given 180 days to resolve reported code execution bugs. This policy applies to 3rd-party developers as well as Microsoft’s own applications and is a great addition to Microsoft’s existing policy of scanning and reviewing app submissions.”

This new policy from Microsoft is significant for businesses that rely on Microsoft platforms and devices. Six months is still a long time for a vulnerability to be in place—especially Critical or Important vulnerabilities that can potentially be exploited to execute malicious code remotely—but the policy shows Microsoft's continued commitment to security. The policy applies to all apps available through the Windows Store, Windows Phone Store, Office Store, or Azure Marketplace."

The policy does not, however, apply to vulnerabilities that are being actively exploited in the wild. Flaws that pose an imminent or ongoing threat are handled with greater urgency. According to a blog post from Microsoft, "In those cases, we’ll work with the developer to have an update available as soon as possible and may remove the app from the store earlier."

If you have Automatic Updates enabled, sit back and relax, but plan on your system rebooting at some point to finish applying all of the necessary patches. If you don’t use Automatic Updates, get cracking! You’ve got a lot of Critical patches to install.

Follow me on Twitter @sajilpl