[BLACK HAT] Googlers have lately found not one but two more security vulnerabilities in Intel and AMD processors that can be exploited to steal sensitive data from a vulnerable computer's memory. . Specifically, there's one flaw in Intel components, and one in AMD. Both can be abused by malware running on a system, or a rogue logged-in user, to lift passwords, secrets, and other data out of memory that should be off limits. This should be concerning for those who use shared servers in the cloud. The Intel vulnerability, found by Daniel Moghimi and dubbed Downfall , was addressed on Tuesday, nearly a year after its private disclosure. The AMD vulnerability, found by Tavis Ormandy and named Zenbleed , was patched , to a degree, in July after being reported privately in mid-May, as we previously covered . . Recent vulnerabilities identified in Intel and AMD processors present significant risks for data leakage, threatening the security of cloud-based servers.. Intel Data Leak, AMD Security Flaw, Memory Breach, Cloud Malware, Processor Vulnerabilities. . Brittany Day
Google has released an update for Chrome 15 which addresses a high-risk vulnerability. The security issue is the result of an out-of-bounds memory write in the browser's JavaScript engine. . Under normal circumstances such a vulnerability would allow remote code execution and would be considered critical. However, because Google Chrome uses a native sandbox that prevents attackers from executing malicious code, the severity of the bug was downgraded. The link for this article located at InfoWorld is no longer available. . Mozilla has rolled out a patch for Firefox 85 addressing a critical buffer overflow vulnerability, significantly improving its safety.. Chrome Update, High Risk Vulnerability, Remote Code Execution, Browser Update. . LinuxSecurity.com Team
The OpenSSL developers have released versions 0.9.8o and 1.0.0a, fixing two security problems. A flaw in the ASN.1 parser can be exploited to write to invalid memory addresses using specially crafted "Cryptographic Message Syntax" (CMS) structures. . The flaw potentially allows arbitrary code to be injected in order to compromise a system. CMS is not enabled by default in the 0.9.8 branch of OpenSSL, but it is enabled in the 1.0.0 branch. An uninitialised buffer in the EVP_PKEY_verify_recover() function in version 1.0.0 can be exploited to make an invalid RSA key appear to be valid. Since very few applications have used this recently-introduced function, the scope of this problem is limited. The OpenSSL developers say that pkeyutl is currently one of the only OpenSSL tools to access this function. [All of article] The link for this article located at H Security is no longer available. . The flaw potentially allows arbitrary code to be injected in order to compromise a system. CMS is no. openssl, developers, released, versions, fixing, security, problems. . LinuxSecurity.com Team
Mozilla has announced the release of Firefox 3.6.3 to address a critical security hole used as part of a winning exploit at Pwn2Own 2010. The update comes just over a week after the release of Firefox 3.6.2 which addressed a different critical flaw.. The memory corruption flaw, demonstrated by Nils of MWR Infosecurity at Pwn2Own 2010, is caused by moving DOM nodes between documents and triggering garbage collection at the right time, leaving an incorrectly retained node which would be used later. This, in turn, could be used to execute remotely injected code. Mozilla say the exploit only affects Firefox 3.6, but that it plans to patch Firefox 3.5 in a coming release "just in case there is an alternate way of triggering the bug". There are no other changes in Firefox 3.6.3. The developers recommend that all Firefox 3.6 users upgrade to the new version, either by waiting for the automated update notification or by manually selecting "Check for updates" from the Help Menu. [All of article] The link for this article located at H Security is no longer available. . Google unveiled Chrome 84.0 to address a significant security vulnerability revealed at DEF CON 2020, recommending that users upgrade promptly.. Mozilla Firefox Update, Memory Corruption, Remote Code Execution. . LinuxSecurity.com Team
Mozilla has released an update to its Firefox browser, fixing a widely publicized flaw in the open-source software. The 2.0.0.10 update fixes a handful of memory corruption flaws that crash Firefox, and a cross-site request forgery flaw that could give attackers a way to get unauthorized access to certain Web sites. But the most anticipated bug fix in this release addresses a problem in the way Firefox processes files that are compressed using the .jar (Java Archive) format. What's your opinion on how browsers like Firefox handles special Web links that are used to execute possibly harmful application? Are they doing enough to help prevent these types of attacks? . The link for this article located at linuxworld is no longer available. . Google enhances Chrome to fix vulnerabilities related to memory management and cross-origin request problems that endanger user safety.. Mozilla Firefox Update, Memory Corruption Fix, Cross-Site Request Security, Web App Security. . Bill Locke
Get the latest Linux and open source security news straight to your inbox.