<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Texas AgriLife Security</title>
	
	<link>http://ait-security.tamu.edu</link>
	<description>Teaching, Research, Extension and Service</description>
	<lastBuildDate>Fri, 17 Feb 2012 14:20:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/TexasAgrilifeSecurity" /><feedburner:info uri="texasagrilifesecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
		<title>Summary of Microsoft and third party patches for February</title>
		<link>http://ait-security.tamu.edu/2012/02/17/summary-of-microsoft-and-third-party-patches-for-february/</link>
		<comments>http://ait-security.tamu.edu/2012/02/17/summary-of-microsoft-and-third-party-patches-for-february/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 14:14:48 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[february patches]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=576</guid>
		<description><![CDATA[If I was going to try to summarize the scope of patches for February the term that comes to mind is ‘massive’.  February not only included nine security patches for 21 vulnerabilities in almost all current Microsoft products including Windows Client Operating Systems, Windows Server Operating Systems, Internet Explorer, Windows Media Player, Visio (Viewer), SharePoint, ...]]></description>
			<content:encoded><![CDATA[<p>If I was going to try to summarize the scope of patches for February the term that comes to mind is ‘massive’.  February not only included nine security patches for 21 vulnerabilities in almost all current Microsoft products including Windows Client Operating Systems, Windows Server Operating Systems, Internet Explorer, Windows Media Player, Visio (Viewer), SharePoint, and .NET/Silverlight, but several third party vendors also released updates on February 14/15. These products include:  Adobe Flash (which included addressing a vulnerability that was actively being exploited), Adobe Shockwave, Oracle Java and also Google Chrome.</p>
<p>In light of the scope of the patches, the <strong>February ISO recommendation would be as follows: </strong></p>
<ul>
<li><strong>Patch all workstations as soon as possible with both Microsoft </strong>(especially patch MS12-010 and also MS12-013)<strong> and third party updates; </strong></li>
<li><strong>Patch all server installations as soon as time permits. </strong></li>
</ul>
<p>To the knowledge of the AgriLife ISO, with the exception of the MS12-016 patch for Silverlight 4, no problems have been experienced with the installation of these patches.  Early in the patch release on February 14, customers reported that some Windows 7, Vista and XP machines (both 32 and 64 bit) experienced an error when the KB2668562 patch installation was attempted.  That condition has since been identified as a problem with metadata (logic) error.  The patch was re-released later in the day on February 14.  See the following URL for details -  <a href="http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_update/kb2668562-silverlight-update-will-not-install-feb/46bcf0b1-c9b8-41f5-b802-b6a8e822d930">http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_update/kb2668562-silverlight-update-will-not-install-feb/46bcf0b1-c9b8-41f5-b802-b6a8e822d930</a></p>
<p><strong>Details on specific products patched by bulletin </strong></p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-008">http://technet.microsoft.com/en-us/security/bulletin/ms12-008</a> &#8211; Windows workstation and Server OSs</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-009">http://technet.microsoft.com/en-us/security/bulletin/ms12-009</a> &#8211; Windows workstation and Server OSs</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-010">http://technet.microsoft.com/en-us/security/bulletin/ms12-010</a> &#8211; Internet Explorer version 6-9</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-011">http://technet.microsoft.com/en-us/security/bulletin/ms12-011</a> &#8211; SharePoint</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-012">http://technet.microsoft.com/en-us/security/bulletin/ms12-012</a> &#8211; Windows Server 2008 OSs only</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-013">http://technet.microsoft.com/en-us/security/bulletin/ms12-013</a> &#8211; Windows workstation and Server OSs excluding Windows XP and Server 2003</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-014">http://technet.microsoft.com/en-us/security/bulletin/ms12-014</a> &#8211; Windows XP workstation only</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-015">http://technet.microsoft.com/en-us/security/bulletin/ms12-015</a> &#8211; Microsoft Visio viewer 2010 base and SP1 (32 and 64 bit)</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-016">http://technet.microsoft.com/en-us/security/bulletin/ms12-016</a>  -  .NET framework 2.0, 3.51, 4.0 and Silverlight</li>
</ul>
<p><strong>Patches by bulletin &#8211; details<br />
Workstation/server OS – Bulletin #8</strong> – two vulnerabilities in Windows Kernel Mode Drivers &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-008">http://technet.microsoft.com/en-us/security/bulletin/ms12-008</a></p>
<p>NOTE – Remote code execution vulnerability. Two vulnerabilities addressed; one had not previously publicly disclosed, the second HAD been disclosed publicly. For the vulnerability that had NOT been publicly disclosed, it is expected that reliable exploit code will materialize in the next 30 days. For the vulnerability that HAD been publicly disclosed, reliable exploit code is not expected to materialize within the next 30 days.</p>
<p>Applicable workstation operating systems and severity:</p>
<ul>
<li>Windows XP-SP3 (32 bit) – CRITICAL</li>
<li>Windows XP-SP2 (64 bit) – CRITICAL</li>
<li>Windows Vista-SP2 (32 and 64 bit) – CRITICAL</li>
<li>Windows 7 base and SP1 (32 and 64 bit) – CRITICAL</li>
</ul>
<p><strong>Server OS – Bulletin #8</strong></p>
<p>Applicable server operating systems and severity:</p>
<ul>
<li>Windows Server 2003-SP2 (32 and 64 bit) – CRITICAL</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – CRITICAL/IMPORTANT*</li>
<li>Windows Server 2008R2-SP2 (64 bit) and Itanium – CRITICAL/IMPORTANT*</li>
</ul>
<p>*NOTE – Server core operating system affected – See the following URLS for details &#8211; <a href="http://technet.microsoft.com/en-us/library/ee441255%28WS.10%29.aspx">http://technet.microsoft.com/en-us/library/ee441255%28WS.10%29.aspx</a> or <a href="http://technet.microsoft.com/en-us/library/ff698994%28WS.10%29.aspx">http://technet.microsoft.com/en-us/library/ff698994%28WS.10%29.aspx</a></p>
<p>For the following Server operating systems, severity is classified as IMPORTANT if Server Core installation option is used: Server 2008 SP2 (32 and 64 bit), Server 2008R2 (64 bit)</p>
<p><strong>Workstation/server OS – Bulletin #9</strong> – two vulnerabilities in Windows Ancillary Function Driver- <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-009">http://technet.microsoft.com/en-us/security/bulletin/ms12-009</a></p>
<p>NOTE – Elevation of privilege (to exploit this vulnerability, an attacker would require valid logon credentials and be required to login locally).  Privately disclosed vulnerability. Reliable exploit code expected within the next 30 days now the vulnerability has been made public. First vulnerability (CVE-2012-0149) only affects Windows Server 2003.  Second vulnerability affects all 64 bit versions of current Windows workstation and Server operating systems.</p>
<p>Applicable workstation operating systems and severity:</p>
<ul>
<li>Windows XP-SP2 (64 bit) – IMPORTANT</li>
<li>Windows Vista-SP2 (64 bit) – IMPORTANT</li>
<li>Windows 7 base and SP1 (64 bit) – IMPORTANT</li>
</ul>
<p><strong>Server OS – Bulletin #9</strong></p>
<p>Applicable workstation operating systems and severity:</p>
<ul>
<li>Windows Server 2003 SP2 (32, 64 bit and Itanium) – IMPORTANT</li>
<li>Windows Server 2008 SP2 (64 bit and Itanium) – IMPORTANT</li>
<li>Windows Server 2008R2 base and SP1 – (64 bit and Itanium) &#8211; IMPORTANT</li>
</ul>
<p><strong>Workstation/server OS – Bulletin #10</strong> – Four vulnerabilities in Internet Explorer versions 6-9 <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-010">http://technet.microsoft.com/en-us/security/bulletin/ms12-010</a></p>
<p>NOTE – Remote Code Execution vulnerabilities.  None of the vulnerabilities have been disclosed publicly prior to February 14. Likely to see reliable exploit code within the next 30 days now the vulnerabilities are publicly known.</p>
<p>Applicable workstation OS and Web Browsers and severity:</p>
<ul>
<li>Windows XP-SP3 (32 bit) – CRITICAL for Internet Explorer versions 7 and 8</li>
<li>Windows XP-SP2 (64 bit) – CRITICAL for Internet Explorer versions 7 and 8</li>
<li>Windows Vista-SP2 (32 and 64 bit) – CRITICAL for Internet Explorer versions 7, 8 and 9</li>
<li>Windows 7 – base and SP1 (32 and 64 bit) – CRITICAL for Internet Explorer 8 and 9</li>
</ul>
<p><strong>Server OS – Bulletin #10</strong></p>
<p>Applicable workstation operating systems and severity:</p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium) – MODERATE for Internet Explorer version 7 and 8</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – MODERATE for Internet Explorer version 7-9</li>
<li>Windows Server 2008R2 base and SP1 (64 bit and Itanium) – MODERATE for Internet Explorer version 8 and 9</li>
</ul>
<p><strong>Application software – Bulletin #11 </strong>-<strong>  </strong>three Cross Site Scripting vulnerabilities in SharePoint and SharePoint foundation &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-011">http://technet.microsoft.com/en-us/security/bulletin/ms12-011</a></p>
<p>NOTE – Elevation of privilege (to exploit this vulnerability, an attacker would require valid logon credentials and be required to login locally).  Privately disclosed vulnerability. Reliable exploit code likely to materialize in the next 30 days. Exposure mitigated for users accessing SharePoint servers with Internet Explorer versions 8 and 9 due to cross site scripting blocking implemented in Internet Explorer (versions 8 and 9).</p>
<p>Applicable application software and Severity –</p>
<ul>
<li>Microsoft Office SharePoint 2010 base and SP1 – IMPORTANT</li>
<li>Microsoft Office SharePoint Foundation 2010 base and SP1 – IMPORTANT</li>
</ul>
<p><strong>Server OS – Bulletin #12</strong> – one vulnerability in Windows Color Control panel &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-012">http://technet.microsoft.com/en-us/security/bulletin/ms12-012</a></p>
<p>NOTE – Remote code execution. Publicly disclosed vulnerability. Reliable exploit code likely to materialize in the next 30 days.  Not applicable for Windows Client Operating Systems</p>
<p>Applicable Server OSs and severity</p>
<ul>
<li>Windows Server 2008-SP2 (32 and 64 bit) – IMPORTANT*</li>
<li>Windows Server 2008-SP2 (Itanium) – IMPORTANT</li>
<li>Windows Server 2008R2 – 64 bit – IMPORTANT*</li>
<li>Windows Server 2008R2 – Itanium &#8211; IMPORTANT</li>
</ul>
<p>*NOTE Server core installation not affected</p>
<p><strong>Workstation/server OS – Bulletin #13</strong> – one vulnerability in Windows C Run-Time Library &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-013">http://technet.microsoft.com/en-us/security/bulletin/ms12-013</a></p>
<p>NOTE – Remote code execution. Privately reported vulnerability. Reliable exploit code likely to materialize in the next 30 days.</p>
<p>Applicable workstation OSs and severity</p>
<ul>
<li>Windows XP-SP2 – NOT applicable</li>
<li>Windows Vista-SP2 (32 and 64 bit) – CRITICAL</li>
<li>Windows 7-base and SP1 (32 and 64 bit) – CRITICAL</li>
</ul>
<p>Applicable Server OSs and severity</p>
<ul>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – CRITICAL*</li>
<li>Windows Server 2008R2 base and SP1 (64 bit an Itanium) – CRITICAL*</li>
</ul>
<p>*Note server core operating system installation affected for 32 and 64 bit versions. Itanium installations not affected.</p>
<p><strong>Workstation/server OS – Bulletin  #14</strong> – one vulnerability in Indeo Codec &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-014">http://technet.microsoft.com/en-us/security/bulletin/ms12-014</a></p>
<p>NOTE – Remote code execution. Publicly reported. Reliable exploit code likely to materialize in the next 30 days.</p>
<p>Applicable workstation OSs and severity</p>
<ul>
<li>Windows XP-SP3 – (32 bit) – IMPORTANT</li>
<li>Windows Vista-SP2 (32 and 64 bit) – NOT applicable</li>
<li>Windows 7-base and SP1 (32 and 64 bit) – NOT applicable</li>
</ul>
<p>Applicable Server OSs and severity</p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium) – NOT applicable</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – NOT applicable</li>
<li>Windows Server 2008R2 base and SP1 (64 bit an Itanium) &#8211;  NOT applicable</li>
</ul>
<p><strong>Application software – Bulletin #15</strong> – five vulnerabilities in Visio 2010 viewer &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-015">http://technet.microsoft.com/en-us/security/bulletin/ms12-015</a></p>
<p>NOTE – Remote code execution. Privately reported. Reliable exploit code likely to materialize in the next 30 days.</p>
<p>Applicable applications and severity</p>
<ul>
<li>Microsoft Visio viewer 2010 base and SP1 – (32 and 64 bit) &#8211; IMPORTANT</li>
</ul>
<p><strong>Workstation and Server OSs and Development Tools and Software – Bulletin #16</strong> – one vulnerability in .NET framework (versions 2.0, 3.51 and 4) and Silverlight &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-016">http://technet.microsoft.com/en-us/security/bulletin/ms12-016</a></p>
<p>NOTE &#8211; Remote code execution. Publicly reported. Reliable exploit code likely to materialize in the next 30 days.</p>
<p>&nbsp;</p>
<p>Applicable workstation OSs and severity</p>
<ul>
<li>Windows XP-SP3  (32 and 64 bit) &#8211; CRITICAL</li>
<li>Windows Vista-SP2 (32 and 64 bit) – CRITICAL</li>
<li>Windows 7 base and SP1 – (32 and 64  bit) &#8211; CRITICAL</li>
</ul>
<p>&nbsp;</p>
<p>Applicable server OSs and severity</p>
<ul>
<li>Windows Server 2003SP2 – 32, 64 bit and Itanium – CRITICAL</li>
<li>Windows Server 2008SP2 – 32, 64 bit and Itanium – CRITICAL</li>
<li>Windows Server 2008R2 base and SP1 – 64 bit and Itanium &#8211; CRITICAL</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/02/17/summary-of-microsoft-and-third-party-patches-for-february/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new version of Java was released on February 14</title>
		<link>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-java-was-released-on-february-14/</link>
		<comments>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-java-was-released-on-february-14/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 15:11:48 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[java update]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=574</guid>
		<description><![CDATA[Oracle released a new version of Java on February 14.  The most current releases are 1.6.31 and 1.7.03. They can be downloaded from the links below Oracle-Java – 1.6.31 -  http://java.com/en/download/manual.jsp 1.7.03 -   http://www.oracle.com/technetwork/java/javase/downloads/index-jsp-138363.html#javasejdk  (as of yet not considered a production release)]]></description>
			<content:encoded><![CDATA[<p>Oracle released a new version of Java on February 14.  The most current releases are 1.6.31 and 1.7.03. They can be downloaded from the links below</p>
<p><strong>Oracle-Java – </strong></p>
<p>1.6.31 -  <a href="http://java.com/en/download/manual.jsp">http://java.com/en/download/manual.jsp</a></p>
<p>1.7.03 -  <a href="http://www.oracle.com/technetwork/java/javase/downloads/index-jsp-138363.html#javasejdk"> http://www.oracle.com/technetwork/java/javase/downloads/index-jsp-138363.html#javasejdk</a>  (as of yet not considered a production release)</p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-java-was-released-on-february-14/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new version of Google Chrome was released on Feb 15</title>
		<link>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-google-chrome-was-released-on-feb-15/</link>
		<comments>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-google-chrome-was-released-on-feb-15/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 14:22:34 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[chrome update]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=572</guid>
		<description><![CDATA[On February 15,  Google released a new version of Chrome. The updated version addresses a number of stability issues and security vulnerabilities and also includes a new version of flash. The current version of Google Chrome is 17.0.963.56.    It can be downloaded from http://www.google.com/chrome]]></description>
			<content:encoded><![CDATA[<p>On February 15,  Google released a new version of Chrome. The updated version addresses a number of stability issues and security vulnerabilities and also includes a new version of flash. The current version of Google Chrome is 17.0.963.56.    It can be downloaded from <a href="http://www.google.com/chrome"><cite>http://www.<strong>google</strong>.com/<strong>chrome</strong></cite></a></p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-google-chrome-was-released-on-feb-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new version of Adobe Flash was released on Feb 15</title>
		<link>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-adobe-flash-was-released-on-feb-15/</link>
		<comments>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-adobe-flash-was-released-on-feb-15/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 14:01:50 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[flash update]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=570</guid>
		<description><![CDATA[Adobe released a new version of Flash on Wednesday, February 15 to address vulnerabilities identified in the previous version. The updated version can be downloaded from &#8211; http://get.adobe.com/flashplayer/ The current versions for the various platforms are as follows: Windows/Macintosh/Linux/Solaris &#8211; 11.1.102.62 Android 4 &#8211; 11.1.115.6 Android 3 and earlier &#8211; 11.1.111.6]]></description>
			<content:encoded><![CDATA[<p>Adobe released a new version of Flash on Wednesday, February 15 to address vulnerabilities identified in the previous version. The updated version can be downloaded from &#8211; <a href="http://get.adobe.com/flashplayer/">http://get.adobe.com/flashplayer/</a></p>
<p>The current versions for the various platforms are as follows:</p>
<ul>
<li>Windows/Macintosh/Linux/Solaris &#8211; 11.1.102.62</li>
<li>Android 4 &#8211; 11.1.115.6</li>
<li>Android 3 and earlier &#8211; 11.1.111.6</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/02/16/a-new-version-of-adobe-flash-was-released-on-feb-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox and Thunderbird version 10 released – Extended Support Release also now available.</title>
		<link>http://ait-security.tamu.edu/2012/02/02/firefox-version-10-released-extended-support-release-also-now-available/</link>
		<comments>http://ait-security.tamu.edu/2012/02/02/firefox-version-10-released-extended-support-release-also-now-available/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 16:24:10 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[firefox esr]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=568</guid>
		<description><![CDATA[Version 10 of Firefox and Thunderbird were released on January 31. Several security fixes have been implemented. With the release of Firefox version 10, Mozilla has also begun deployment of the Extended Support Release &#8211; https://wiki.mozilla.org/Enterprise/Firefox/ExtendedSupport:Proposal The Extended Support Release will provide large organizations (such as Universities, Schools, City/State governments) additional time (when compared to ...]]></description>
			<content:encoded><![CDATA[<p>Version 10 of Firefox and Thunderbird were released on January 31. Several security fixes have been implemented.</p>
<p>With the release of Firefox version 10, Mozilla has also begun deployment of the Extended Support Release &#8211; <a href="https://wiki.mozilla.org/Enterprise/Firefox/ExtendedSupport:Proposal%20">https://wiki.mozilla.org/Enterprise/Firefox/ExtendedSupport:Proposal</a></p>
<p>The Extended Support Release will provide large organizations (such as Universities, Schools, City/State governments) additional time (when compared to Mozilla normal 8 week release cycle), for testing and deployment of new versions. Mozilla has currently proposed that the Extended Support Release versions will be supported for a period of 54 weeks. During that period, critical and important security patches will be applied to Extended Support Releases (and they will appear as point releases coinciding with normal version updates for Firefox and Thunderbird)   However, other enhancements will not be back ported.</p>
<p>The link to download Firefox ESR (for various operating systems) is available at the bottom of the <a href="http://www.mozilla.org/en-US/firefox/organizations/faq">http://www.mozilla.org/en-US/firefox/organizations/faq</a>/ URL.</p>
<p>Additional details about ESR is available at the following URLs<br />
<a href="http://www.mozilla.org/en-US/firefox/organizations/faq">http://www.mozilla.org/en-US/firefox/organizations/</a><br />
<a href="http://www.mozilla.org/en-US/firefox/organizations/faq/%20%20">http://www.mozilla.org/en-US/firefox/organizations/faq/  </a></p>
<p>&nbsp;</p>
<p><strong>NOTE:</strong> A ESR version of Thunderbird is also available &#8211; information (including a download link) on the Thunderbird ESR version is available at: <a href="http://www.mozilla.org/en-US/thunderbird/organizations/faq/">http://www.mozilla.org/en-US/thunderbird/organizations/faq/</a></p>
<p><strong>Update February 2</strong></p>
<p>Release notes for version 10 can be found at &#8211; <a href="http://www.mozilla.org/en-US/firefox/10.0/releasenotes/">http://www.mozilla.org/en-US/firefox/10.0/releasenotes/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/02/02/firefox-version-10-released-extended-support-release-also-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security update issued for Apple Snow Leopard and Lion – February 1</title>
		<link>http://ait-security.tamu.edu/2012/02/02/security-update-issued-for-apple-snow-leopard-and-lion-february-1/</link>
		<comments>http://ait-security.tamu.edu/2012/02/02/security-update-issued-for-apple-snow-leopard-and-lion-february-1/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 16:15:39 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Apple security update]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=565</guid>
		<description><![CDATA[On February 1, Apple released several security updates for the Snow Le0pard (10.6.8) and Lion (10.7.*) operating systems.  There are 39 vulnerabilities addressed in the security update. The updated release is known as 10.7.3. Details about the new release are available at the following URL:  http://support.apple.com/kb/HT5130 The following products have security updates included: Address book ...]]></description>
			<content:encoded><![CDATA[<p>On February 1, Apple released several security updates for the Snow Le0pard (10.6.8) and Lion (10.7.*) operating systems.  There are 39 vulnerabilities addressed in the security update. The updated release is known as 10.7.3. Details about the new release are available at the following URL:  <a href="http://support.apple.com/kb/HT5130">http://support.apple.com/kb/HT5130</a></p>
<p>The following products have security updates included:</p>
<ul>
<li>Address book</li>
<li>Apache</li>
<li>ATS</li>
<li>CFNetwork</li>
<li>ColorSync</li>
<li>CoreAudio</li>
<li>CoreMedia</li>
<li>CoreText</li>
<li>CoreUI</li>
<li>Curl</li>
<li>Data Security</li>
<li>Dovecot</li>
<li>filecmds</li>
<li>ImageIO</li>
<li>Internet Sharing</li>
<li>Libinfo</li>
<li>Libresolv</li>
<li>Libsecurity</li>
<li>OpenGL</li>
<li>PHP</li>
<li>QuickTime</li>
<li>SquirrelMail</li>
<li>Subversion</li>
<li>TimeMachine</li>
<li>Tomcat</li>
<li>WebDAV Sharing</li>
<li>WebMail</li>
<li>X11</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/02/02/security-update-issued-for-apple-snow-leopard-and-lion-february-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerabilities in Symantec pc-Anywhere</title>
		<link>http://ait-security.tamu.edu/2012/01/26/vulnerabilities-in-symantec-pc-anywhere/</link>
		<comments>http://ait-security.tamu.edu/2012/01/26/vulnerabilities-in-symantec-pc-anywhere/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 15:52:32 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[pc-anywhere]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=563</guid>
		<description><![CDATA[Several severe vulnerabilities have recently been identified in Symantec pcAnywhere. Please see the following link for details. http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&#38;pvid=security_advisory&#38;year=2012&#38;suid=20120124_00 Security Advisories Relating to Symantec Products &#8211; Symantec pcAnywhere Remote Code Execution, Local Access File Tampering &#160; Update &#8211; February 1 In the URL below, Symantec has recently rescinded its recommendation to discontinue use of all versions ...]]></description>
			<content:encoded><![CDATA[<p>Several severe vulnerabilities have recently been identified in Symantec pcAnywhere. Please see the following link for details.</p>
<ul>
<li><a href="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120124_00">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120124_00</a></li>
</ul>
<p>Security Advisories Relating to Symantec Products &#8211; Symantec pcAnywhere Remote Code Execution, Local Access File Tampering</p>
<p>&nbsp;</p>
<p><strong>Update &#8211; February 1</strong></p>
<p>In the URL below, Symantec has recently rescinded its recommendation to discontinue use of all versions of pcAnywhere. It has also indicated that all customers running a version prior to 12.0 that free upgrades will be offered to version 12.5</p>
<p><a href="http://www.networkworld.com/news/2012/013112-symantec-drops-dont-use-advice-gives-255552.html">http://www.networkworld.com/news/2012/013112-symantec-drops-dont-use-advice-gives-255552.html</a></p>
<p>Modena also confirmed that customers running versions of pcAnywhere prior to version 12.0 will be offered a free upgrade to 12.5.</p>
<p>&#8220;If requested, Symantec will honor an update to version 12.5 for customers using previous versions of the product,&#8221; said Modena today. To ask for a free upgrade, users should send the company an email aimed at the pcanywhere@symantec.com address.</p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/01/26/vulnerabilities-in-symantec-pc-anywhere/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advance notice of January Microsoft patches for Windows OSs and Applications</title>
		<link>http://ait-security.tamu.edu/2012/01/05/advance-notice-of-january-microsoft-patches-for-windows-oss-and-applications/</link>
		<comments>http://ait-security.tamu.edu/2012/01/05/advance-notice-of-january-microsoft-patches-for-windows-oss-and-applications/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 21:30:10 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[microsoft january patches]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=559</guid>
		<description><![CDATA[Microsoft has just sent their advance notice of the patches that are scheduled to be released on Tuesday, January 10.  There are a total of seven patches to be released for January.  All but one of the patches apply to Windows Workstation and Server Operating Systems. The one exception applies to Microsoft Developer Tools and ...]]></description>
			<content:encoded><![CDATA[<p>Microsoft has just sent their advance notice of the patches that are scheduled to be released on Tuesday, January 10.  There are a total of seven patches to be released for January.  All but one of the patches apply to Windows Workstation and Server Operating Systems. The one exception applies to Microsoft Developer Tools and Software.</p>
<p>All but one of the patches are classified as IMPORTANT. The one exception is classified as CRITICAL on Windows Server 2003 and 2008, Windows XP and Windows Vista operating systems (for Windows 7 and Windows Server 2008R2 installations, the same patch is classified as IMPORTANT) and will require a restart of the specific system being updated.</p>
<p>The primary rationale for the classification of CRITICAL for bulletin #1 on Windows Server 2003, Server 2008 and Windows XP/Vista systems is the vulnerability could allow remote code execution if exploited.</p>
<p>&nbsp;</p>
<p>The following details are currently unknown and should be made available on Tuesday:</p>
<ul>
<li>If the exploit has been identified to the public</li>
<li>If the exploit code requires an authenticated account for the vulnerability to be exploited successfully.</li>
<li>If the vulnerability can be exploited consistently with security features* included in the most current Windows operating (such as Windows Server 2008R2 and Windows 7)</li>
</ul>
<p>Each of these factors will determine the urgency for the application of the critical patch.</p>
<p>*Security features implemented by default in the most current operating systems include:<br />
<a href="http://en.wikipedia.org/wiki/Address_space_layout_randomization">http://en.wikipedia.org/wiki/Address_space_layout_randomization</a><br />
<a href="%20http://en.wikipedia.org/wiki/Data_Execution_Prevention%20">http://en.wikipedia.org/wiki/Data_Execution_Prevention</a></p>
<p><strong>Update &#8211; January 10, 4 p.m.</strong></p>
<p>Additional information has been recently provided detailing the scope of the Microsoft patches released on January 10. It is available at &#8211; <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-jan">http://technet.microsoft.com/en-us/security/bulletin/ms12-jan</a></p>
<p>As originally indicated, Microsoft has only identified one patch as being critical for workstations and servers -  <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-004">http://technet.microsoft.com/en-us/security/bulletin/ms12-004</a> . However, one other source (<a href="http://isc.sans.edu/diary/January+2012+Microsoft+Black+Tuesday+Summary/12361">http://isc.sans.edu/diary/January+2012+Microsoft+Black+Tuesday+Summary/12361</a>) has recommended that TWO patches should be applied to workstations<em> immediately</em>  (<a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-004">http://technet.microsoft.com/en-us/security/bulletin/ms12-004</a> and <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-005">http://technet.microsoft.com/en-us/security/bulletin/ms12-005</a> ) and also that the MS12-004 and MS12-005 patches be applied to servers as soon as possible. The ISC-SANs source has also identified patch MS12-002 as critical for workstations.</p>
<p>&nbsp;</p>
<p>There are currently no known exploits identified for these vulnerabilities.  However, it is fully expected that exploit code WILL made available within the next 30 days.</p>
<p>&nbsp;</p>
<p>The breakdown of vulnerabilities and the potential for exploitation is as follows:</p>
<p><strong>Workstation OS &#8211; Bulletin #1 – Security Feature Bypass &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-001">http://technet.microsoft.com/en-us/security/bulletin/ms12-001</a></p>
<p>NOTE – Security Feature Bypass vulnerability. Reliable exploit code is expected. Vulnerability has not been publically disclosed as of this time.</p>
<ul>
<li>Windows XP–SP3 32bit – <em>NOT APPLICABLE</em></li>
<li>Windows XP-SP2 64bit – IMPORTANT</li>
<li>Windows Vista-SP2 – 32 and 64 bit – IMPORTANT</li>
<li>Windows 7 – base and SP1 both 32 and 64 bit – IMPORTANT</li>
</ul>
<p><strong>Server OS – Bulletin #1 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-001">http://technet.microsoft.com/en-us/security/bulletin/ms12-001</a></p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium systems) &#8211; IMPORTANT</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium systems) &#8211; IMPORTANT</li>
<li>Windows Server 2008R2- base and SP1 (64 bit and Itanium systems) – IMPORTANT</li>
</ul>
<p><strong>Workstation OS &#8211; Bulletin #2 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-002">http://technet.microsoft.com/en-us/security/bulletin/ms12-002</a></p>
<p>NOTE – Remote Code Execution vulnerability. Reliable exploit code is expected at a future date. Vulnerability has not been publically disclosed as of this time.</p>
<ul>
<li>Windows XP-SP3 32bit – IMPORTANT*</li>
<li>Windows XP-SP2 64bit – IMPORTANT*</li>
<li>Windows Vista-SP2 – <em>NOT APPLICABLE </em>for 32 or 64 bit Vista systems</li>
<li>Windows 7-SP1 – <em>NOT APPLICABLE</em> for 32 or 64 bit Windows 7 systems</li>
</ul>
<p>*NOTE – Identified as CRITICAL for Workstation OSs by SANS &#8211; <a href="http://isc.sans.edu/diary/January+2012+Microsoft+Black+Tuesday+Summary/12361">http://isc.sans.edu/diary/January+2012+Microsoft+Black+Tuesday+Summary/12361</a></p>
<p><strong>Server OS – Bulletin #2 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-002">http://technet.microsoft.com/en-us/security/bulletin/ms12-002</a></p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium) &#8211; IMPORTANT</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – <em>NOT APPLICABLE</em> for Server 2008 installations</li>
<li>Windows Server 2008R2-base and SP1 (64 bit and Itanium) – <em>NOT APPLICABLE</em> for Server 2008R2 installations</li>
</ul>
<p><strong>Workstation OS- Bulletin #3 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-003">http://technet.microsoft.com/en-us/security/bulletin/ms12-003</a></p>
<p>NOTE – Elevation of Privilege vulnerability. Reliable exploit code is expected at a future date. Vulnerability has not been publically disclosed as of this time. <em>Applicable for systems running Asian (Chinese, Japanese or Korean) versions of Windows only</em></p>
<ul>
<li>Windows XP–SP3 32bit – IMPORTANT</li>
<li>Windows XP-SP2 64bit – IMPORTANT</li>
<li>Windows Vista-SP2 (32 and 64 bit) – IMPORTANT</li>
<li>Windows 7-SP1 (32 and 64 bit) – <em>NOT APPLICABLE</em></li>
</ul>
<p><strong>Server OS – Bulletin #3 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-003">http://technet.microsoft.com/en-us/security/bulletin/ms12-003</a></p>
<ul>
<li>Windows Server 2003-SP2 – (32, 64 bit and Itanium) IMPORTANT</li>
<li>Windows Server 2008-SP2 – (32, 64 bit and Itanium) IMPORTANT</li>
<li>Windows Server 2008R2-base and SP1 &#8211; (64bit and Itanium) <em>NOT APPLICABLE</em> for Server 2008R2 installations</li>
</ul>
<p><strong>Workstation OS – Bulletin #4 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-004">http://technet.microsoft.com/en-us/security/bulletin/ms12-004</a></p>
<p>NOTE – Remote Code Execution vulnerability. Reliable exploit code is expected at a future date. Vulnerability has not been publically disclosed as of this time.</p>
<ul>
<li>Windows XP-SP3 (32 bit) – CRITICAL</li>
<li>Windows XP-SP2 (64 bit) – CRITICAL</li>
<li>Windows Vista-SP2 (32 and 64 bit) – CRITICAL</li>
<li>Windows 7-SP1 (32 and 64 bit) – IMPORTANT</li>
</ul>
<p>NOTE – For workstations, a <strong><em>patch now</em></strong> action is recommended by ISC-SANs for this vulnerability.</p>
<p><strong>Server OS – Bulletin #4 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-004">http://technet.microsoft.com/en-us/security/bulletin/ms12-004</a></p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium) – CRITICAL</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – CRITICAL</li>
<li>Windows Server 2008R2-base and SP1 (64 bit and Itanium) – IMPORTANT</li>
</ul>
<p><strong>Workstation OS – Bulletin #5 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-005">http://technet.microsoft.com/en-us/security/bulletin/ms12-005</a></p>
<p>NOTE – Remote Code Execution vulnerability. Reliable exploit code is expected at a future date. Vulnerability has not been publically disclosed as of this time.</p>
<ul>
<li>Windows XP-SP3 (32 bit) – IMPORTANT</li>
<li>Windows XP-SP2 (64 bit) – IMPORTANT</li>
<li>Windows Vista-SP2 (32 and 64 bit) – IMPORTANT</li>
<li>Windows 7-SP1 (32 and 64 bit) – IMPORTANT</li>
</ul>
<p>NOTE – For workstations, a <strong><em>patch now</em></strong> action is recommended by ISC-SANs for this vulnerability.</p>
<p><strong>Server OS – Bulletin #5 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-005">http://technet.microsoft.com/en-us/security/bulletin/ms12-005</a></p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium) – IMPORTANT</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – IMPORTANT</li>
<li>Windows Server 2008R2-base and SP1 (64 bit and Itanium) – IMPORTANT</li>
</ul>
<p>NOTE – For server operating systems, the ISC-SANs source assigns a critical classification for this vulnerability.</p>
<p><strong>Workstation OS &#8211; Bulletin #6 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-006">http://technet.microsoft.com/en-us/security/bulletin/ms12-006</a></p>
<p>NOTE – Information Disclosure vulnerability. Reliable exploit code is NOT expected to materialize. Vulnerability has been disclosed publically.</p>
<ul>
<li>Windows XP–SP3 32bit – IMPORTANT</li>
<li>Windows XP-SP2 64bit – IMPORTANT</li>
<li>Windows Vista-SP2 – 32 and 64 bit – IMPORTANT</li>
<li>Windows 7 – base and SP1 both 32 and 64 bit – IMPORTANT</li>
</ul>
<p><strong>Server OS – Bulletin #6 </strong></p>
<ul>
<li>Windows Server 2003-SP2 (32, 64 bit and Itanium) – IMPORTANT</li>
<li>Windows Server 2008-SP2 (32, 64 bit and Itanium) – IMPORTANT</li>
<li>Windows Server 2008R2-base and SP1 (64 bit and Itanium) – IMPORTANT</li>
</ul>
<p><strong>Anticross Site Scripting Library (aka Anti XCSS) &#8211; Bulletin #7 &#8211; </strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-007">http://technet.microsoft.com/en-us/security/bulletin/ms12-007</a></p>
<p>NOTE – Information Disclosure vulnerability. Reliable exploit code is NOT expected to materialize. Vulnerability has been disclosed publically.</p>
<p><strong>Workstation OSs – Bulletin #7</strong></p>
<ul>
<li>All current workstation OSs that have the Anti XCSS library implemented</li>
</ul>
<p><strong>Server OS – Bulletin #7 </strong></p>
<ul>
<li>All current server OSs that have the Anti XCSS library implemented</li>
</ul>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/01/05/advance-notice-of-january-microsoft-patches-for-windows-oss-and-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Out of Band patch issued for ASP.NET implementations</title>
		<link>http://ait-security.tamu.edu/2012/01/02/out-of-band-patch-issued-for-asp-net-implementations/</link>
		<comments>http://ait-security.tamu.edu/2012/01/02/out-of-band-patch-issued-for-asp-net-implementations/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 16:39:16 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[asp.net]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=557</guid>
		<description><![CDATA[On Thursday, December 29, Microsoft released an out of band patch to address a vulnerability identified in ASP.NET applications. If exploited, the vulnerability will cause a denial of service event. If you have ASP.NET applications on your webserver, it is recommended that this patch be applied as soon as possible. Please see details at the ...]]></description>
			<content:encoded><![CDATA[<p>On Thursday, December 29, Microsoft released an out of band patch to address a vulnerability identified in ASP.NET applications. If exploited, the vulnerability will cause a denial of service event. If you have ASP.NET applications on your webserver, it is recommended that this patch be applied as soon as possible.</p>
<p>Please see details at the following URLs –<br />
<a href="http://technet.microsoft.com/en-us/security/advisory/2659883">http://technet.microsoft.com/en-us/security/advisory/2659883</a><br />
<a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx%20">http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx</a><br />
<a href="http://blogs.technet.com/b/srd/archive/2011/12/29/asp-net-security-update-is-live.aspx">http://blogs.technet.com/b/srd/archive/2011/12/29/asp-net-security-update-is-live.aspx</a><br />
<a href="%20http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx%20">http://blogs.technet.com/b/msrc/archive/2011/12/30/december-2011-out-of-band-security-bulletin-webcast-q-amp-a.aspx</a></p>
<p>Specific details regarding the exploit<br />
General Information<br />
<strong>Executive Summary</strong><br />
<em>This security update resolves one publicly disclosed vulnerability and three privately reported vulnerabilities in Microsoft .NET Framework. The most severe of these vulnerabilities could allow elevation of privilege if an unauthenticated attacker sends a specially crafted web request to the target site. An attacker who successfully exploited this vulnerability could take any action in the context of an existing account on the ASP.NET site, including executing arbitrary commands. In order to exploit this vulnerability, an attacker must be able to register an account on the ASP.NET site, and must know an existing user name.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2012/01/02/out-of-band-patch-issued-for-asp-net-implementations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updates to Firefox, Thunderbird and SeaMonkey released on December 20</title>
		<link>http://ait-security.tamu.edu/2011/12/21/updates-to-firefox-thunderbird-and-seamonkey-released-on-december-20/</link>
		<comments>http://ait-security.tamu.edu/2011/12/21/updates-to-firefox-thunderbird-and-seamonkey-released-on-december-20/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 14:47:14 +0000</pubDate>
		<dc:creator>jcbraden</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[mozilla updates]]></category>

		<guid isPermaLink="false">http://agrilife.org/ait-security/?p=553</guid>
		<description><![CDATA[On Tuesday, December 20, updates were issued for Firefox, Thunderbird and SeaMonkey to address security vulnerabilities.  For those of you that have customers who use these products, please have them update to version 9.0 (and version 2.6 for SeaMonkey) Currently I don’t see version 9 of Thunderbird available for downloading at this time – I ...]]></description>
			<content:encoded><![CDATA[<p>On Tuesday, December 20, updates were issued for Firefox, Thunderbird and SeaMonkey to address security vulnerabilities.  For those of you that have customers who use these products, please have them update to version 9.0 (and version 2.6 for SeaMonkey)</p>
<p>Currently I don’t see version 9 of Thunderbird available for downloading at this time – I expect the web page will be updated shortly.</p>
<p>&nbsp;</p>
<p><a href="http://www.mozilla.org/en-US/firefox/all.html">http://www.mozilla.org/en-US/firefox/all.html</a> &#8211; All language versions available at this link.</p>
<p><a href="http://www.mozilla.org/en-US/thunderbird/all.html">http://www.mozilla.org/en-US/thunderbird/all.html</a>  &#8211; All language versions available at this link.</p>
<p><a href="http://www.seamonkey-project.org/releases/seamonkey2.6/">http://www.seamonkey-project.org/releases/seamonkey2.6/</a> -</p>
<p>Additional details.</p>
<p><a href="http://secunia.com/advisories/47302/">http://secunia.com/advisories/47302/</a></p>
<p>&nbsp;</p>
<p>Criticality level   Highly critical</p>
<p>Impact Unknown</p>
<p>Exposure of sensitive information</p>
<p>System access</p>
<p>Where   From remote</p>
<p>Software:</p>
<p>Mozilla Firefox 8.x</p>
<p>Mozilla Thunderbird 8.x</p>
<p>Description</p>
<p>Multiple vulnerabilities have been reported in Mozilla Firefox and Thunderbird, where one has an unknown impact and others can be exploited by malicious people to disclose sensitive information and compromise a user&#8217;s system.</p>
<p>&nbsp;</p>
<p>1) Some unspecified errors can be exploited to corrupt memory. No further information is currently available.</p>
<p>&nbsp;</p>
<p>2) An error exists within the YARR regular expression library when parsing javascript content.</p>
<p>&nbsp;</p>
<p>3) An error within the SVG implementation when SVG elements are removed during a DOMAttrModified event can be exploited to cause an out-of-bounds memory access.</p>
<p>&nbsp;</p>
<p>4) The application does not properly handle SVG animation accessKey events when JavaScript is disabled. This can lead to the user&#8217;s key strokes being leaked.</p>
<p>&nbsp;</p>
<p>5) An error within the plugin handler when deleting DOM frame can be exploited to dereference memory.</p>
<p>NOTE: This vulnerability only affects Mac OS X.</p>
<p>&nbsp;</p>
<p>6) An error exists within the handling of OGG &lt;video&gt; elements.</p>
<p>Successful exploitation of vulnerabilities #1 &#8211; #3 and #5 may allow execution of arbitrary code.</p>
<p>Solution</p>
<p>Upgrade to version 9.0.</p>
]]></content:encoded>
			<wfw:commentRss>http://ait-security.tamu.edu/2011/12/21/updates-to-firefox-thunderbird-and-seamonkey-released-on-december-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

