CDSA News

Weekend Vulnerability and Patch Report, Sept. 7, 2014 (Citadel Information Group)

Important Security Updates

Dropbox: Dropbox has released version 2.10.29 for its file hosting program. Updates are available at Dropbox’s website.

Google Chrome: Google has released Google Chrome version 37.0.2062.103 for Windows, Mac, and Linux to fix at least 10 highly critical vulnerabilities reported in previous versions. Updates are available from within the browser or from Google Chrome’s website.

Mozilla Firefox: Mozilla has released version 32 to fix at least 7 highly critical unpatched vulnerabilities reported in previous versions. Updates are available within the browser or from Mozilla’s website.

Opera: Opera has released version 24.0.1558.53 to fix multiple moderately critical unpatched vulnerabilities reported in previous versions. Updates are available from within the browser or from Opera’s website.

Skype: Skype has released Skype 6.20.0.104. Updates are available from the program or Skype’s website.

Current Software Versions

Adobe Flash 14.0.0.176 [Windows 7: IE]

Adobe Flash 14.0.0.179 [Windows 7: Firefox, Mozilla]

Adobe Flash 14.0.0.176 [Windows 8: IE]

Adobe Flash 14.0.0.176 [Macintosh OS X: Firefox, Opera, Safari]

Adobe Reader 11.0.08

Dropbox 2.10.29

Firefox 32.0 [Windows]

Google Chrome 37.0.2062.103

Internet Explorer 11.0.9600.17126

Java SE 7 Update 67

QuickTime 7.7.5

Safari 5.1.7 [Windows]

Safari 7.0.4 [Mac OS X]

Skype 6.20.0.104

For Your IT Department

Cisco Multiple Products: Secunia reports Cisco has released an update to fix an unpatched vulnerability in its IOS XR. Upgrade to version 5.1.3.4i.BASE or later. Secunia reports an unpatched vulnerability in Cisco’s Transport Gateway for Small Call Home reported in versions 3.6 and 4.0. Other versions may also be affected. No official solution is currently available.

McAfee Multiple Products: Secunia reports McAfee has released an update to fix multiple vulnerabilities reported in previous versions. Apply hotfixes HF988208 and HF983758 or update to version 5.1.2 when available (Scheduled to be released Q1 2015). Secunia reports McAffee has released an update to fix multiple vulnerabilities reported in previous versions. Apply hotfix HF983759 or update to version 4.6.9 when available (Scheduled to be released Q1 2015).

Novell Groupwise: Secunia reports Novell has released an update to Groupwise to fix a security bypass vulnerability reported in previous versions. Apply Support Pack 1 (SP1) or later.

WordPress: US-Cert reports WordPress has released an update to address multiple vulnerabilities. WordPress 3.7.3 or 3.8.3 users will be updated to 3.7.4 or 3.8.4. Users operating older, unsupported versions of WordPress are encouraged to upgrade to 3.9.2.