Showing posts with label linksys. Show all posts
Showing posts with label linksys. Show all posts

Monday, April 29, 2013


WEEKEND VULNERABILITY AND PATCH REPORT
April 28, 2013
The following software vulnerabilities and updates were announced by Citadel Information Group.  They strongly recommend that readers update their computers and take other action as indicated.  This is from an e-mail received from Stan Stahl, Ph.D. [www.citadel-information.com] and posted with his approval.

Important Security Updates

RoboForm: Roboform has released version 7.8.8.5. Download the update from Roboform's website.  
Gallery Project: GalleryProject.org has released version 3.0.7 to fix a vulnerability in Gallery report in prior versions. Update to version 3.0.7 which can be found on Gallery's website.  
HP LaserJet Printers: HP has released firmware updates for many of its LaserJet Printers. The firmware fixes a less critical vulnerability. Click here to see a list of the specific models affected and click here to find instructions for updating the firmware.

Current Software Versions

Adobe Flash 11.7.700.169 [Windows 7: IE9, Firefox, Mozilla, Netscape, Opera]
Adobe Flash 11.7.700.169 [Windows 8: IE]
Adobe Flash 11.7.700.169 [Macintosh OS X: Firefox, Opera, Safari]
Adobe Reader 11.0.02
Dropbox 1.6.11 [Citadel warns against relying on Dropbox security. We recommend files containing sensitive information be independently encrypted with a program like Axcrypt; encryption keys be at least 15 characters long; and the Dropbox password be at least 15 characters long and different from other passwords.]
Firefox 20.0.1 [Windows]
Google Chrome 26.0.1410.64
Internet Explorer 10.0.9200.16521 [Windows 7: IE]
Internet Explorer 10.0.9200.16519 [Windows 8: IE]
Java SE 7 Update 21 [Citadel recommends removing or disabling Java from your browser. Java is a major source of cyber criminal exploits. It is not needed for most internet browsing. If you have particular web sites that requires Java, Citadel recommends using a two-browser approach to minimize risk. If you normally browse the Web with Firefox, for example, disable the Java plugin in Firefox and use an alternative browser - such as Chrome, IE9, Safari, etc - with Java enabled to browse only the sites that require it.]
QuickTime 7.7.3 (1680.64)
Safari 5.1.7  [Windows]
Safari 6.0.4 [Mac OS X]
Skype 6.3.0.105

Newly Announced Unpatched Vulnerabilities

Belkin Advance N900 Dual-Band Wireless Router: Secunia reports an unpatched vulnerability in Belkin's Advance N900 Dual-Band Wireless Router in firmware version 1.00.06. Other versions may also be affected. No official solution is currently available. 
Belkin N300 Wi-Fi N Router: Secunia reports an unpatched vulnerability in Belkin's N300 Wi-Fi Router in firmware version 1.00.06. Other versions may also be affected. No official solution is currently available. 
D-Link DIR-300 / DIR-615 Wireless Router: Secunia reports an unpatched vulnerability in D-Link's Wireless Routers; DIR-300 Rev A version 1.05 and DIR-615 Rev D3 version 4.13. Secunia reports a second unpatched vulnerability in D-Link's DIR-615 Rev D3 version 4.13. Other versions may also be affected. No official solution is currently available. 
Linksys WRT310N Wireless Router: Secunia reports an unpatched vulnerability in  Linksys' WRT310N Wireless Router in firmware version 2.0.0.1. Other versions may also be affected. No official solution is currently available. 
NetGear WNDR4700 Wireless Router: Secunia reports an unpatched moderately critical vulnerability in NetGear's WNDR4700 Wireless Router in version 1.0.0.34. Other versions may also be affected. No official solution is currently available. 
TP-LINK TD-8817 Wireless Router: Secunia reports an unpatched vulnerability in TP-LINK's TD-8817 Wireless Router in version 6.0.1 Build 111128 Rel.26763. Other versions may also be affected. No official solution is currently available. 
TP-LINK WR1043N Wireless Router: Secunia reports an unpatched vulnerability in TP-LINK's WR1043N Wireless Router in version TL-WR1043ND_V1_120405. Other versions may also be affected. No official solution is currently available. 
For an updated list of previously announced Unpatched Vulnerabilities, please see the resources section of Citadel's website.

For Your IT Department

Cisco Unpatched Products: Secunia reports unpatched security issues with Cisco's Firewall Services Module reported in version 4.1(5) and ASA Software versions 8.2(5) and 8.4(0.3). No official solutions are currently available. 
Cisco Multiple Products: Cisco has released updates for multiple products, including Cisco's NX-OS-based products, Cisco Device Manager, and Cisco Unified Computing System,  and others. Apply appropriate updates.
Citrix CloudPlatform: Citrix has released an update to fix at least 3 moderately critical vulnerabilities reported in versions 3.0.x through 3.0.6 with patch B. Apply security patch.
Citrix NetScaler / Access Gateway: Citrix has released an update to fix a moderately critical vulnerability. Apply appropriate patch.
Citrix Xen Server: Citrix has released an update to fix a vulnerability reported in versions 6.1 and prior. Apply patches.
Firefox FirePHP: Firefox has released an update to fix a weakness in the FirePHP extension for Firefox. Update to version 0.7.2.
HP Managed Printing Administration: HP has released an update to its Managed Printing Administration to fix a vulnerability reported in previous versions. Update to version 2.7.0.
IBM Security AppScan / Java Vulnerabilities: IBM has released version 8.6.0.1 to fix at least 20 vulnerabilities, some of which are highly critical, in IBM Security AppScan Standard versions 8.0 and 8.5 bundled with Java. Previous versions remain unpatched.
Ipswitch IMail Server: Ipswitch has released an update to fix a vulnerability in its IMail Server reported in previous versions of the bundled version of OpenSSL. Update to version 12.3.
Joomla!: Joomla! has released updates to fix at least 6 moderately critical vulnerabilities in Joomla! reported in versions prior to 2.5.10 and 3.1.0. Update to version 2.5.10 or 3.1.0.
Joomla! ALFContact Component: Secunia reports a vulnerability in Joomla!'s ALFContact Component in version 3.1. Otherversions may also be affected. No official solution is currently available.
McAfee ePolicy Orchestrator: McAfee has released version 8.6.0.1 to fix at least 2 moderately critical vulnerabilities reported in versions 4.5.6 and prior and versions 4.6.5 and prior. Apply patches.
VMware Products / Java Vulnerabilities: VMware has released a partial fix to address at least 30 highly critical vulnerabilities reportedly found in the following products and versions bundled with Java: vCenter Server version 5.0,vCenter Server version 4.1, Update Manager version 5.1, Update Manager version 5.0, ESX version 4.1. Apply patch if available.
VMware vCenter Server: VMware has released an update to its Server Products to fix at least 40 vulnerabilities, some of which are highly critical. Update to version 5.1 Update 1. 
If you are responsible for the security of your computer, Citadel's Weekend Vulnerability and Patch Report is for you. We strongly urge you to take action to keep your workstation patched and updated.
If someone else is responsible for the security of your computer, forward our Weekend Vulnerability and Patch Report to them and follow up to make sure your computer has been patched and updated.
Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer's computers.
Citadel publishes our Weekend Vulnerability and Patch Report to alert readers to some of the week's important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.
Copyright © 2013 Citadel Information Group. All rights reserved.

Monday, April 22, 2013


WEEKEND VULNERABILITY AND PATCH REPORT
April 21, 2013

The following software vulnerabilities and updates were announced by Citadel Information Group.  They strongly recommend that readers update their computers and take other action as indicated.  This is from an e-mail received from Stan Stahl, Ph.D. [www.citadel-information.com] and posted with his approval.

Important Security Updates

Apple Java for OS X: Apple has released an update to OS X to fix at least 21 highly critical vulnerabilities in its version of Java. Download the update from Apple's website.
Apple Safari for OS X: Apple has released version 6.0.4. of Safari for OS X to fix a highly critical vulnerability. Download the update from Apple's website. This update is for OS X only and doesn't affect the Windows version.
Foxit 6.02.0413: Foxit has released a security and performance update. The updated program can be obtained from Foxit's web site
NetGear WNR1000: NetGear has released version 1.0.2.60 for its WNR1000 Wireless Router to fix a vulnerability. Download the update from NetGear's website by providing the model number of the router.
Oracle Java: Oracle has released Java  SE 7 Update 21 to fix at least 42 highly critical vulnerabilities in  Java. Download the update from the Java website.
Picasa 3.9, build 136.20: Picasa has released a security and performance update. The updated program can be obtained from Picasa's website.
VLC Media Player: VLC has released version 2.0.6 to its Media Player to fix a highly critical vulnerability reported in version 2.05 and prior. Download the version from VLC's website. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, February 3, 2013. 

Current Software Versions

Adobe Flash 11.7.700.169 [Windows 7: IE9, Firefox, Mozilla, Netscape, Opera]
Adobe Flash 11.7.700.169 [Windows 8: IE]
Adobe Flash 11.7.700.169 [Macintosh OS X: Firefox, Opera, Safari]
Adobe Reader 11.0.02
Dropbox 1.6.11 [Citadel warns against relying on Dropbox security. We recommend files containing sensitive information be independently encrypted with a program like Axcrypt; encryption keys be at least 15 characters long; and the Dropbox password be at least 15 characters long and different from other passwords.]
Firefox 20.0.1 [Windows]
Google Chrome 26.0.1410.64
Internet Explorer 10.0.9200.16521 [Windows 7: IE]
Internet Explorer 10.0.9200.16519 [Windows 8: IE]
Java SE 7 Update 21 [Citadel recommends removing or disabling Java from your browser. Java is a major source of cyber criminal exploits. It is not needed for most internet browsing. If you have particular web sites that requires Java, Citadel recommends using a two-browser approach to minimize risk. If you normally browse the Web with Firefox, for example, disable the Java plugin in Firefox and use an alternative browser - such as Chrome, IE9, Safari, etc - with Java enabled to browse only the sites that require it.]
QuickTime 7.7.3 (1680.64)
Safari 5.1.7  [Windows]
Safari 6.0.4 [Mac OS X]
Skype 6.3.0.105

Newly Announced Unpatched Vulnerabilities

D-Link DIR-865L Wireless Router: Secunia reports an unpatched vulnerability in D-Link's DIR-865-L Wireless Router in version 1.03. There is currently no patch at this time.
Linksys EA2700 Wireless Router: Secunia reports unpatched vulnerabilities in Linksys' EA2700 Wireless Router in firmware version 1.0.12.128947. There is currently no patch at this time. 
Linksys WRT54GL Wireless Router: Secunia reports an unpatched vulnerability in D-Link's DIR-865-L Wireless Router in firmware version 4.30.15. There is currently no patch at this time. 
For an updated list of previously announced Unpatched Vulnerabilities, please see the resources section of Citadel's website.

For Your IT Department

Cisco Multiple Products: Cisco has released updates for multiple products, including its Adaptive Security Appliance, NAC appliance,  and others. Apply appropriate updates.
Novell GroupWise: Novell has released an update for its GroupWise WebAccess to fix a vulnerability. Apply appropriate patches.
Oracle Multiple Products: US-CERT and Secunia reports that Oracle has released updates for at least 31 of its products, including Oracle Database Server, E-Business Suite, Supply Chain Products Suite, PeopleSoft, My SQL and others. Apply appropriate updates.
If you are responsible for the security of your computer, Citadel's Weekend Vulnerability and Patch Report is for you. We strongly urge you to take action to keep your workstation patched and updated.
If someone else is responsible for the security of your computer, forward our Weekend Vulnerability and Patch Report to them and follow up to make sure your computer has been patched and updated.
Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer's computers.
Citadel publishes our Weekend Vulnerability and Patch Report to alert readers to some of the week's important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.
Copyright © 2013 Citadel Information Group. All rights reserved.

Monday, January 28, 2013


WEEKEND SOFTWARE VULNERABILITY AND PATCH REPORT
January 27, 2013
The following software vulnerabilities and updates were announced by Citadel Information Group.  They strongly recommend that readers update their computers and take other action as indicated.  This is from an e-mail received from Stan Stahl, Ph.D. [www.citadel-information.com] and posted with his approval.

Imporant Security Updates

Google Chrome: Google has released Chrome, version 24.0.1312.56. to fix at least 5 highly critical vulnerabilities. Updates are available through the program or from Chrome's website.
Linksys WRT54GL Wireless Router: Linksys has released and update to its WRT54GL Wireless Router. Update to firmware version 4.30.16 by downloading from the Linksys website.

Current Software Versions

Adobe Flash 11.5.502.146 [Windows 7: IE9, Firefox, Mozilla, Netscape, Opera]
Adobe Flash 11.3.378.5 [Windows 8: IE]
Adobe Flash 11.5.502.146 [Macintosh OS X: Firefox, Opera, Safari]
Adobe Reader 11.0.01
Dropbox 1.6.11 [Citadel warns against relying on Dropbox security. We recommend files containing sensitive information be independently encrypted with a program like Axcrypt; encryption keys be at least 15 characters long; and the Dropbox password be at least 15 characters long and different from other passwords.]
Firefox 18.0.1 [Windows]
Google Chrome 24.0.1312.56
Internet Explorer 9.0.8112.16421 [Windows 7: IE], [See warning below]
Internet Explorer 10.0.9200.16466 [Windows 8: IE]
Java SE 7 Update 11 [Citadel recommends removing or disabling Java from your browser. Java is a major source of cyber criminal exploits. It is not needed for most internet browsing. If you have particular web sites that requires Java, Citadel recommends using a two-browser approach to minimize risk. If you normally browse the Web with Firefox, for example, disable the Java plugin in Firefox and use an alternative browser - such as Chrome, IE9, Safari, etc - with Java enabled to browse only the sites that require it.]
QuickTime 7.7.3 (1680.64)
Safari 5.1.7  [Windows, See warning below]
Safari 6.0.2 [Mac OS X]
Skype 6.1.0.129

For Your IT Department

Cisco Wireless LAN Controllers: Secunia reports vulnerabilities in multiple Cisco Wireless LAN Controllers. Apply applicable updates.
Google Web Toolkit: Secunia reports a vulnerability in Google's Web Toolkit. Update to version 2.5 GA.
PDF-XChange Viewer: Secunia reports a highly critical vulnerability in PDF-XChange Viewer. Update to version 2.5 Build 208.0.
Sourcefire Snort: Secunia reports a moderately critical vulnerability in Sourcefire's Snort. Update Snort rules to a version released on 2013-01-17 or later.
WordPress: Secunia reports at least 37 moderately critical vulnerabilities in WordPress. Update to version 3.5.1. There are also plugin vulnerabilities for updates.

Important Unpatched Vulnerabilities

Android Browser: Secunia reports a less critical vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.
AOL downloadUpdater2 Firefox Plugin: Secunia reports a highly critical vulnerability in version 1.3.0.0. Other versions may also be affected. No solution is currently available. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 12, 2012.
Apple Safari for Windows: Secunia reports a moderately critical vulnerability in Apple's Safari version 5.1.2 (7534.52.7) on Windows using the RealPlayer and Adobe Flash plug-ins. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 11, 2012.
Apple Safari for Windows: Secunia reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.
CA ARCserve Backup: Secunia reports a less critical vulnerability in CA's ARCserver Backup in versions 12.0, 12.5, 15, and 16. CA provides a partial fix solution and advises updating to a fixed version. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 25, 2012.  
HTC Mobile Devices: The security vulnerability in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, February 11, 2011.
HTC Touch2: The highly critical 0-day vulnerability in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 18, 2011.
McAfee SaaS: The highly critical vulnerability in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, January 22, 2012.  
Microsoft Windows XP: A less-critical security vulnerability has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 7, 2011.
Microsoft Word: A highly critical vulnerability has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, June 19, 2011.
Microsoft Reader: The highly critical vulnerability in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, April 15, 2011.
PDF-Pro: Several highly critical vulnerabilities in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 4, 2011.
Quick View Plus CorelDRAW: A highly critical vulnerability has been found in Quick View Plus which can be exploited by malicious people to compromise a user's system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, July 31, 2011.
Samsung / Dell Printers: Secunia reports a moderately critical security issue in Samsung's ML-2580 and ML-4050 Monochrome Laser Printers and Dell's 2145cn and 2335dn Multifunction Printers. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 2, 2012.
Samsung Galaxy S III: Secunia reports two highly critical vulnerabilities in the Galaxy S3 device. We first alerted readers tothis vulnerability in Weekend Vulnerability and Patch Report, October 14, 2012.
Symantec pcAnywhere: As we reported in our Cyber Security News of the Week, January 29, 2012, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.
VLC Media Player: As we reported in our Cyber Security News of the Week, December 16, 2012, Secunia reports a highly critical vulnerability in the VLC Media Player. No patch is available at this time.
ACD Systems: Citadel recommends users remove all ACD Systems programs from their computers. ACD Systems has failed to patch significant critical vulnerabilities in their programs dating back more than a year. Consequently Citadel recommends users remove all ACD Systems programs from their computers until the company fixes these vulnerabilities and pays proper attention to the implications of their security vulnerabilities in opening doors to cyber criminals . The community cannot tolerate a head-in-the-sand attitude, whether by developers or the people who purchase and use their programs. The consequences of willful ignorance are too grave.

If you are responsible for the security of your computer, our weekly report is for you. We strongly urge you to take action to keep your workstation patched and updated.
If someone else is responsible for the security of your computer, forward our Weekend Vulnerability and Patch Report to them and follow up to make sure your computer has been patched and updated.
Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer's computers.
Citadel publishes our Weekend Vulnerability and Patch Report to alert readers to some of the week's important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.