CDSA News

Weekend Vulnerability and Patch Report, Feb. 1, 2015 (Citadel Information Group)

Important Security Updates

Adobe Flash Player: Adobe has released version 16.0.0.296 to fix an extremely critical vulnerability reported in previous versions. Updates are available from Adobe’s website.

Apple iOS: Apple has released version 8.1.3 of its iOS to fix at least 23 highly critical vulnerabilities reported in previous versions. The update is available through the devices or through Apple’s website.

Apple iTunes: Apple has released version 12.1.0 (32-bit) of iTunes. Updates are available from Apple’s website.

Apple OS X: Apple has released updates for OS X to fix at least 45 highly critical vulnerabilities. Apply Security Update 2015-001 or update to version 10.10.2. Updates are available from Apple’s website.

Apple Safari: Apple has released updates for Safari to fix at least 4 highly critical vulnerabilities reported in previous versions. Update to version 6.2.3, 7.1.3, or 8.0.3. Updates are available from Apple’s website.

Apple TV: Apple has released version 7.0.3 for Apple TV to fix at least 20 highly critical vulnerabilities. Updates are available through the device or Apple’s website.

Google Chrome: Google has released Google Chrome version 40.0.2214.93. Updates are available from within the browser or from Google Chrome’s website.

Mozilla Firefox: Mozilla has released version 35.0.1. Updates are available within the browser or from Mozilla’s website.

Opera: Opera has released version 27 to fix multiple moderately critical unpatched vulnerabilities reported in previous versions. Updates are available from within the browser or from Opera’s website.

Piriform CCleaner: Piriform has released version 5.02.5101 for CCleaner. Updates are available from Piriform’s website.

Skype: Skype has released Skype 7.1.59.105. Updates are available from the program or Skype’s website.

Current Software Versions

Adobe Flash 16.0.0.296 [Windows 7: IE]

Adobe Flash 16.0.0.296 [Windows 7: Firefox, Mozilla]

Adobe Flash 16.0.0.296 [Windows 8: IE]

Adobe Flash 16.0.0.296 [Macintosh OS X: Firefox, Opera, Safari]

Adobe Reader 11.0.10

Dropbox 3.0.5

Firefox 35.0.1

Google Chrome 40.0.2214.93

Internet Explorer 11.0.9600.17501

Java SE 8 Update 31

QuickTime 7.76.80.95

Safari 5.1.7

Safari 7.1.3 [Mac OS X]

Skype 7.1.59.105

For Your IT Department

Cisco Multiple Products: Secunia reports Cisco has released updates for its Identity Services Engine (ISE), Unified Computing System (UCS), and others. Apply updates. Secunia reports unpatched vulnerabilities in Cisco’s Unified Communications Domain Manager (CUCDM) and ACNS (Application and Content Networking System). No official solution is available.

VMware Multiple Products: Secunia reports McAfee has released updates for its vCenter Server, Fusion, ESXi, Workstation and Player, vSphere Data Protection, and others. Apply updates.