Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Vendors/Products - Page 36

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Vendors/Products News

Mozilla Firefox 3.6.2: Critical Browser Security Advisory on Web Fonts

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Mozilla released Firefox 3.6.2 late Monday to fix a critical security hole involving Web-based font technology. "We strongly recommend that all Firefox users upgrade to this latest release. If you already have Firefox 3.6 you will receive an automated update notification within 24 to 48 hours. This update can also be applied manually by selecting 'Check for Updates...' from the Help menu," Mozilla's director of Firefox, Mike Beltzner, said in a blog post..

Mozilla: Firefox 3.6 Critical Code Injection Threat and Fix

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Mozilla confirmed the presence of an unpatched flaw in its browser on Thursday, with a post promising to release a fix at the end of the month. The flaw, discovered by security researcher Evgeny Legerov and reported by The Reg last month, creates a means to inject hostile code on vulnerable systems. The vulnerability is due to be fixed in version 3.6 of Firefox on 30 March.

Chrome 4.1.249.1036 High Risk Update: 11 Flaws Fixed Before Contest

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Google [1] has patched 11 vulnerabilities [2] in the Windows version of Chrome [3], including one that earned its finder the first $1,337 check from the company's new bug bounty program. Like Apple [4], which updated Safari last week [5], Google beefed up the security [6] of its browser just days before the Pwn2Own browser [7] hacking [8] contest was to kick off in Canada.

PHP 5.2: Critical Security Advisory for Safe_Mode Bypass

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

An update which fixes around 40 bugs is available for the PHP 5.2 development branch. Version 5.2.13 comes highly recommended for all PHP 5.2.x users, as it includes a number of security-related fixes. These include a bug when validating the safe_mode configuration variable in the tempnam() function which arises when the path does not end in /). An open_basedir/safe_mode bypass vulnerability in the session extension has also been fixed.

Exploring Chromium OS On Older Systems For Cost And Security Benefits

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Most of this article was written on a six-year-old computer running Google's new Chromium OS. "Chromium OS" is the open-source version of the new Chrome OS that Google is developing for netbooks, tablets, and other lightweight machines. It's built from the source code that Google is making widely available, but it runs on standard hardware. Google's Chrome OS, in contrast, is designed to run on a new generation of stripped-down systems.

AppArmor Integration: Improvements In Linux Kernel Security Framework

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

John Johansen, a developer with commercial Ubuntu sponsor Canonical, has submitted an updated version of the AppArmor security framework to the Linux kernel developers for inspection. Johansen writes that, like the SELinux and Tomoyo solutions already integrated into the kernel, this fourth general posting of AppArmor uses Linux Security Modules (LSM) to hook into the kernel.

Firefox 3.6 Security Advisory - Critical Remote Access Exploit

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Russian security firm Intevydis has made a Windows exploit for a previously unknown security hole in Firefox 3.6 available to its customers. The exploit allows attackers to remotely gain control of a PC. Intevydis develops the commercial VulnDisco add-on for the also commercial Canvas exploit toolkit by vendor Immunity. On the Immunity forum, developer Evgeny Legerov praises his exploit for Windows XP (SP3) and Vista as being quite reliable. The developer says It was an interesting challenge to find the flaw

Your message here