Monday, October 22, 2012

WEEKEND VULNERABILITY AND PATCH REPORT
October 21, 2012
 
The following software vulnerabilities and updates were announced last week. Citadel Information Group strongly recommends that readers update their computers and take other action as indicated.  This is from a e-mail received from Stan Stahl, Ph.D. [www.citadel-information.com].
 

Important Security Updates

Adobe Reader: Adobe has released version 11.0, which can be downloaded from Adobe's website.
Apple Mac OS X for Java: Apple has released an update to Java for Mac OS X to fix at least 20 vulnerabilities, some of which are highly critical. Update to Java Mac OS X 10.6 Update 11, which can be downloaded from Apple's website.
 Oracle Java: Oracle has released an update to Java to fix at least 30 vulnerabilities, some of which are highly critical. Update to Java SE 7 Update 09, which can be downloaded from Oracle's website.See Citadel recommendation below.
 

Current Software Versions

Adobe Flash 11.4.402.287 [Windows: Internet Explorer, Firefox, Mozilla, Netscape, Opera, Safari]
Adobe Flash 11.4.402.287 [Mac OS X: Firefox, Opera, Safari]
Adobe Reader 11.0 [Warning; see below]
Apple QuickTime 7.7.2
Apple Safari 5.1.7  [Warning; see below]
Google Chrome 22.0.1229.94
Internet Explorer 9.0.8112.16421
Java SE 7 Update 09 [Citadel recommends removing or disabling Java from your browser. Java is a major source of cyber criminal exploits. It is not needed for most internet browsing. If you have particular web sites that requires Java, Citadel recommends using a two-browser approach to minimize risk. If you normally browse the Web with Firefox, for example, disable the Java plugin in Firefox and use an alternative browser - such as Chrome, IE9, Safari, etc - with Java enabled to browse only the sites that requires it.]
Mozilla Firefox 16.0.1

Newly Announced Unpatched Vulnerabilities

None

For Your IT Department

McAfee Firewall Enterprise: Secunia reports an unpatched moderately critical vulnerability in McAfee's Firewall Enterprise. Update to version 8.2.1P06 or 8.3.0P02 when available.
McAfee Firewall Enterprise: McAfee has released an update to its Firewall Enterprise to fix a  moderately critical vulnerability. Update to version 7.0.1.03H06.
Oracle: Oracle has released many patches and updates to fix various vulnerabilities, many of which are highly critical, within its products. Check your devices and update as necessary.

Important Unpatched Vulnerabilities

Adobe Reader / Acrobat Multiple Vulnerabilities: Secunia reports highly critical vulnerabilities in Reader X and Acrobat X versions 10.1.4 and prior for Windows and Macintosh; Reader and Acrobat versions 9.5.2 and prior for Windows and Macintosh; and Reader for Linux versions 9.4.7 and prior. Secunia reports several additional highly critical vulnerabilities in versions 9 and X of Reader and Acrobat. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 19, 2012.
Android Browser: Secunia reports a less critical vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.
AOL downloadUpdater2 Firefox Plugin: Secunia reports a highly critical vulnerability in version 1.3.0.0. Other versions may also be affected. No solution is currently available. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 12, 2012.
Apple Safari for Windows: Secunia reports a moderately critical vulnerability in Apple's Safari version 5.1.2 (7534.52.7) on Windows using the RealPlayer and Adobe Flash plug-ins. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 11, 2012.
Apple Safari for Windows: Secunia reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.
CA ARCserve Backup: Secunia reports a less critical vulnerability in CA's ARCserver Backup in versions 12.0, 12.5, 15, and 16. CA provides a partial fix solution and advises updating to a fixed version. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 25, 2012.  
HTC Mobile Devices: The security vulnerability in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, February 11, 2011.
HTC Touch2: The highly critical 0-day vulnerability in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 18, 2011.
McAfee SaaS: The highly critical vulnerability in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, January 22, 2012.  
Microsoft Windows XP: A less-critical security vulnerability has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 7, 2011.
Microsoft Word: A highly critical vulnerability has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, June 19, 2011.
Microsoft Reader: The highly critical vulnerability in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, April 15, 2011.
PDF-Pro: Several highly critical vulnerabilities in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 4, 2011.
Quick View Plus CorelDRAW: A highly critical vulnerability has been found in Quick View Plus which can be exploited by malicious people to compromise a user's system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, July 31, 2011.
Samsung Galaxy S III: Secunia reports two highly critical vulnerabilities in the Galaxy S3 device. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, October 14, 2012.
Symantec pcAnywhere:As we reported in our Cyber Security News of the Week, January 29, 2012, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.
ACD Systems: Citadel recommends users remove all ACD Systems programs from their computers. ACD Systems has failed to patch significant critical vulnerabilities in their programs dating back more than a year. Consequently Citadel recommends users remove all ACD Systems programs from their computers until the company fixes these vulnerabilities and pays proper attention to the implications of their security vulnerabilities in opening doors to cyber criminals . The community cannot tolerate a head-in-the-sand attitude, whether by developers or the people who purchase and use their programs. The consequences of willful ignorance are too grave.
If you are responsible for the security of your computer, our weekly report is for you. We strongly urge you to take action to keep your workstation patched and updated.
If someone else is responsible for the security of your computer, forward our Weekend Vulnerability and Patch Report to them and follow up to make sure your computer has been patched and updated.
Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer's computers.
 
Citadel publishes our Weekend Vulnerability and Patch Report to alert readers to some of the week's important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities

Friday, October 19, 2012


Fine-Tuning Capital Gains and Losses

The year's end has historically been a good time to plan tax savings by carefully structuring capital gains and losses. Let's consider some possibilities.

If there are losses to date - As an example, suppose the stocks and other capital assets that were sold during the year result in a net loss and that there are other investment assets still owned by the taxpayer that have appreciated in value. Consideration should be given to whether any of the appreciated assets should be sold (if their value has peaked), thereby offsetting those gains with pre-existing losses.

Long-term capital losses offset long-term capital gains before they offset short-term capital gains. Similarly, short-term capital losses offset short-term capital gains before they offset long-term capital gains. Keep in mind that taxpayers may use up to $3,000 of total capital losses in excess of total capital gains as a deduction against ordinary income in computing adjusted gross income (AGI). Individuals are subject to tax at a rate as high as 35% on short-term capital gains and ordinary income. But long-term capital gains are generally taxed at a maximum rate of 15%.

All of this means that having long-term capital losses offsetting long-term capital gains should be avoided, since those losses will be more valuable if they are used to offset short-term capital gains or ordinary income. Avoiding this requires making sure that the long-term capital losses are not taken in the same year as the long-term capital gains. However, this is not just a tax issue; investment factors also need to be considered. It would not be wise to defer recognizing gain until the following year if there is too much risk that the property's value will decline before it can be sold. Similarly, one wouldn't want to risk increasing a loss on property that is expected to continue declining in value by deferring its sale until the following year.

To the extent that taking long-term capital losses in a different year than long-term capital gains is consistent with good investment planning, a taxpayer should take steps to prevent those losses from offsetting those gains.

If there are no net capital losses so far for the year - If a taxpayer expects to realize such losses in the subsequent year well in excess of the $3,000 ceiling, consider shifting some of the sales and resulting excess losses into the current year. That way, the losses can offset current year gains, and up to $3,000 of any excess loss will become deductible against ordinary income in the subsequent year.

For the reasons outlined above, paper losses or gains on stocks may be worth recognizing (i.e., selling the stock) this year in some situations. But if the stock is sold at a loss with the idea to repurchase it, the repurchase cannot be within a 61-day period (30 days before or 30 days after the date of sale) under the “wash sale” rules. If it is, the loss will not be recognized and will simply adjust the tax basis of the reacquired stock.

Careful handling of capital gains and losses can save substantial amounts of tax. Please contact this office to discuss year-end planning strategies that apply to your particular situation so as to maximize tax savings.

Wednesday, October 17, 2012


WEEKEND VULNERBILITY AND PATCH REPORT [10-15-2012]
  
The following software vulnerabilities and updates were received via e-mail from Stan Stahl, Ph.D, owner of  Citadel Information Group [www.citadel-information.com]  He strongly recommends that readers update their computers and take other action as indicated.
 

Important Security Updates

Adobe Flash: Adobe has released an update to Flash Player to fix at least 30 vulnerabilities, some of which are highly critical. Update to version 11.4.402.287.

Google Chrome: Google has released an update to Chrome to fix at least 30 vulnerabilities, some of which are highly critical. Update to version 22.0.1229.94 through the browser.
Microsoft Patch Tuesday: Microsoft's Patch Tuesday release addresses seven updates to fix a variety of security issues within Windows, Internet Explorer, Office and other Microsoft products. Many of the patched vulnerabilities are rated extremely or highly critical.
Mozilla Firefox: Mozilla has released updates to Mozilla to fix at least 4 highly critical vulnerabilities. Update to version 16.0.1 through the browser.

 Current Software Versions

*Adobe Flash 11.4.402.287 [Windows: Internet Explorer, Firefox, Mozilla, Netscape, Opera, Safari]
*Adobe Flash 11.4.402.287 [Mac OS X: Firefox, Opera, Safari]
*Adobe Reader 10.1.4 [Warning; see below]
*Apple QuickTime 7.7.2
*Apple Safari 5.1.7  [Warning; see below]
*Google Chrome 22.0.1229.94
*Internet Explorer 9.0.8112.16421
*Java SE 7 Update 07 [Citadel recommends removing or disabling Java from your browser. Java is a major source of cyber criminal exploits. It is not needed for most internet browsing. If you have particular web sites that requires Java, Citadel recommends using a two-browser approach to minimize risk. If you normally browse the Web with Firefox, for example, disable the Java plugin in Firefox and use an alternative browser - such as Chrome, IE9, Safari, etc - with Java enabled to browse only the sites that requires it.]
Mozilla Firefox 16.0.1
 

Newly Announced Unpatched Vulnerabilities

Samsung Galaxy S III: Secunia reports two highly critical vulnerabilities in the Galaxy S3 device. No patch is available at this time.

For Your IT Department

Cisco ASA Products: Cisco has released updates to fix at least 6 moderately critical vulnerabilities in some of its ASA products. Update to the current versions.
Cisco WebEx: Cisco has released updates to fix at least 6 highly critical vulnerabilities in its WebEx Recording Format Player. Update to version 28.4 or 27.32.10.
HP Secure Web Server: HP has released updates to fix at least 7 moderately critical vulnerabilities in its Secure Web Server (SWS) for OpenVMS. Update to version 2.2 Update 2.
Symantec Ghost:  Symantec has released an update to fix a vulnerability in Ghost. Update to version 2.5.1 and apply patch GSS25x_b2620.

Important Unpatched Vulnerabilities

Adobe Reader / Acrobat Multiple Vulnerabilities: Secunia reports highly critical vulnerabilities in Reader X and Acrobat X versions 10.1.4 and prior for Windows and Macintosh; Reader and Acrobat versions 9.5.2 and prior for Windows and Macintosh; and Reader for Linux versions 9.4.7 and prior. Secunia reports several additional highly critical vulnerabilities in versions 9 and X of Reader and Acrobat. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 19, 2012.
Android Browser: Secunia reports a less critical vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.
AOL downloadUpdater2 Firefox Plugin: Secunia reports a highly critical vulnerability in version 1.3.0.0. Other versions may also be affected. No solution is currently available. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 12, 2012.
Apple Safari for Windows: Secunia reports a moderately critical vulnerability in Apple's Safari version 5.1.2 (7534.52.7) on Windows using the RealPlayer and Adobe Flash plug-ins. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 11, 2012.
Apple Safari for Windows: Secunia reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.
CA ARCserve Backup: Secunia reports a less critical vulnerability in CA's ARCserver Backup in versions 12.0, 12.5, 15, and 16. CA provides a partial fix solution and advises updating to a fixed version. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 25, 2012.  
HTC Mobile Devices: The security vulnerability in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, February 11, 2011.
HTC Touch2: The highly critical 0-day vulnerability in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 18, 2011.
McAfee SaaS: The highly critical vulnerability in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, January 22, 2012.  
Microsoft Windows XP: A less-critical security vulnerability has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 7, 2011.
Microsoft Word: A highly critical vulnerability has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, June 19, 2011.
Microsoft Reader: The highly critical vulnerability in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, April 15, 2011.
PDF-Pro: Several highly critical vulnerabilities in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 4, 2011.
Quick View Plus CorelDRAW: A highly critical vulnerability has been found in Quick View Plus which can be exploited by malicious people to compromise a user's system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, July 31, 2011.
Symantec pcAnywhere:As we reported in our Cyber Security News of the Week, January 29, 2012, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.
ACD Systems: Citadel recommends users remove all ACD Systems programs from their computers. ACD Systems has failed to patch significant critical vulnerabilities in their programs dating back more than a year. Consequently Citadel recommends users remove all ACD Systems programs from their computers until the company fixes these vulnerabilities and pays proper attention to the implications of their security vulnerabilities in opening doors to cyber criminals . The community cannot tolerate a head-in-the-sand attitude, whether by developers or the people who purchase and use their programs. The consequences of willful ignorance are too grave.


If you are responsible for the security of your computer, our weekly report is for you. We strongly urge you to take action to keep your workstation patched and updated.

If someone else is responsible for the security of your computer, forward our Weekend Vulnerability and Patch Report to them and follow up to make sure your computer has been patched and updated.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer's computers.

Citadel publishes our Weekend Vulnerability and Patch Report to alert readers to some of the week's important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.

 

Tuesday, October 9, 2012


Arrangements that Recharacterize Taxable Wages as Nontaxable Reimbursements or Allowances

The IRS has provided guidance which clarifies that an arrangement that recharacterizes taxable wages as nontaxable reimbursements or allowances does not satisfy the business connection requirement for accountable expense reimbursement plans.

In general, employee business expense reimbursements that are paid through an employer's accountable expense reimbursement plan are excluded from the employee's adjusted gross income. An accountable plan basically requires employees to submit receipts for expenses and repay any advances that exceed substantiated expenses. Amounts paid to employees through an accountable plan are not taxable compensation. Thus, they are not subject to federal or state income taxes or Social Security taxes, or employer payroll taxes and withholding.

On the other hand, business expense reimbursements paid through a system that does not meet the specific requirements for accountable plans are considered paid under a nonaccountable plan, and are treated as taxable compensation. An employer can have a reimbursement plan that is considered accountable in part and nonaccountable in part.

A reimbursement plan must meet three requirements in order to be considered an accountable expense allowance arrangement

(1)  Reimbursements must have a business connection;

(2)  Reimbursements must be substantiated; and

(3)  Employees must return reimbursements in excess of expenses incurred.

An arrangement satisfies the business connection requirement if it provides advances, allowances, or reimbursements only for business expenses that are allowable as deductions, and that are paid or incurred by the employee in connection with the performance of services as an employee of the employer. Therefore, not only must an employee actually pay or incur a deductible business expense, but the expense must arise in connection with the employment for that employer.

The business connection requirement will not be satisfied if a payer pays an amount to an employee regardless of whether the employee incurs or is reasonably expected to incur deductible business expenses. Failure to meet this reimbursement requirement of business connection is referred to as wage recharacterization because the amount being paid is not an expense reimbursement but rather a substitute for an amount that would otherwise be paid as wages.

The IRS guidance includes four situations, three of which illustrate arrangements that impermissibly recharacterize wages such that the arrangements are not accountable plans. A fourth situation illustrates an arrangement that does not impermissibly recharacterize wages. In this arrangement, an employer prospectively altered its compensation structure to include a reimbursement arrangement.

Because of the difference in tax treatment of reimbursements under an accountable plan versus a nonaccountable plan, it is important to review your reimbursement policies. Please call our office for an appointment to discuss your options under this IRS guidance.

 

Monday, October 1, 2012

3 Tips for Getting an Accurate Business Valuation

If you're conscientious about financial reporting, you may already have a sense of your company's worth, but in some instances you might need a formal business valuation, such as:

• For certain transactions. Selling your business? Planning an IPO? Need financing?
• For tax purposes. Includes estate planning, stock option distribution, and S Corporation conversions.
• For litigation. Needed in cases like bankruptcy, divorce, and damage determinations.

There isn't a single formula for valuing a business, but there are generally-accepted measures that will give you a valid assessment of your company's worth. Here are some tips that will help you get a more accurate business valuation.

1. Take a close look at how your business operates. Does it incorporate the most tax-efficient structure? Have sales been lagging or are you selling most of your merchandise to only a few customers? If so, then consider jump-starting your sales effort by bringing in a seasoned consultant.
Do you have several products that are not selling well? Maybe it's time to remove them from your inventory. Redesign your catalog to give it a fresh new look and make a point of discussing any new and exciting product lines with your existing customer base. It might also be time to give your physical properties a spring cleaning. Even minor upgrades such as a new coat of paint will increase your business valuation.
2. Keep in mind that business valuation is not just an exercise in numbers where you subtract your liabilities from your assets, it's also based on the value of your intangible assets.
It's easy to figure out the numbers for the value of your real estate and fixtures, but what is your intellectual property worth? Do you hold any patents or trademarks? And what about your business relationships or the reputation you've established with existing clients and in the community? Don't forget about key long-term employees whose in-depth knowledge about your business also adds value to its net worth.
3. Choose your appraisal team carefully. Don't try to do it yourself by turning to the Internet or reading a few books. You may eventually need to bring in experts like a business broker and an attorney, but your first step should be to contact us. We have the expertise you need to arrive a fair valuation of your business.

Questions?

Call us toll free at 877-412-3443 for more information.

Please note, to comply with IRS regulations, we need to advise that any discussion of federal tax issues in this blog is not intended or written to be used, and cannot be used by you, (i) to avoid any penalties imposed under the Internal Revenue Code or (ii) to promote, market or recommend to another party any transaction or matter addressed herein. For more information please go to http://www.lw.com/docs/irs.pdf

Weekend Vulnerability and Patch Report

  The following software vulnerabilities and updates were announced last week from a e-mail I received from Stan Stahl, Ph.D.[ www.citadel-information.com].   Citadel Information Group strongly recommends that readers update their computers and take other action as indicated.
 
 Important Security Updates

Apple TV: Apple has released a patch to fix at least 21 highly critical vulnerabilities in its TV product.See Apple website for details on how to update to Apple TV Software version 5.1.

 Foxit Reader: Foxit has released a patch to its Reader to fix a highly critical vulnerability. Update to version 5.4.3 from Foxit's website.

Google Chrome: Google has released version 22.0.1229.79. Download the current version from Google's support website.

Samsung Galaxy S3: As Citadel tweeted last Tuesday, September 25, 2012, Samsung has released a patch to fix the highly critical factory reset vulnerability in its Galaxy S3 device.  Samsung advises checking for software updates through the 'Settings: About device: Software update' menu and installing the current patch with the available over-the-air update.

Current Software Versions

Adobe Flash 11.4.402.278 [Windows: Internet Explorer, Firefox, Mozilla, Netscape, Opera, Safari]
Adobe Flash 11.4.402.265 [Mac OS X: Firefox, Opera, Safari]
Adobe Reader 10.1.4 [Warning; see below]
Apple QuickTime 7.7.2
Apple Safari 5.1.7  [Warning; see below]
Google Chrome 22.0.1229.79
Internet Explorer 9.0.8112.16421
Java SE 7 Update 07 [Citadel recommends removing or disabling Java from your browser. Java is a major source of cyber criminal exploits. It is not needed for most internet browsing. If you have particular web sites that requires Java, Citadel recommends using a two-browser approach to minimize risk. If you normally browse the Web with Firefox, for example, disable the Java plugin in Firefox and use an alternative browser - such as Chrome, IE9, Safari, etc - with Java enabled to browse only the sites that requires it.]
Mozilla Firefox 15.0.1

 Newly Announced Unpatched Vulnerabilities

Java: As Citadel tweeted last Tuesday, September 25, 2012, Seclists.org has discovered additional unpatched critical security flaws in all versions of Java. See above.

For Your IT Department

Adobe: As Citadel tweeted last Friday, September 28, 2012, Adobe has issued a special alert to address an issue with a current Adobe code signing certificate. The certificate will be revoked on October 4, 2012 for all software code signed after July 10, 2012. Adobe is issuing a new digital certificate for all affected products. Adobe published a help page that lists the affected products and contains links to updated versions signed with a new certificate.

 Apple Remote Desktop: Apple has released updates to both of its products, Remote Desktop Admin and Remote Desktop Client. Update as necessary.

Cisco: Cisco has released many patches and updates to fix various vulnerabilities within its products. Check your devices and update as necessary.

Oracle: Oracle has released many patches and updates to fix various vulnerabilities within its products. Check your devices and update as necessary.

Oracle Solaris Mozilla Firefox: Oracle has released an update to Mozilla's Firefox browser thats included in the Solaris operating system to fix 11 highly critical vulnerabilities. Apply all necessary patches.

SafeNet: Secunia reports an unpatched vulnerability in SafeNet's Sentinel Protection product. No official solution is currently available.

SonicWALL Anti-Spam & Email Security: SonicWALL has released an update to fix vulnerabilities in its Anti-Spam & Email Security products. Update to version 7.3.6. 

Important Unpatched Vulnerabilities

Adobe Reader / Acrobat Multiple Vulnerabilities: Secunia reports highly critical vulnerabilities in Reader X and Acrobat X versions 10.1.4 and prior for Windows and Macintosh; Reader and Acrobat versions 9.5.2 and prior for Windows and Macintosh; and Reader for Linux versions 9.4.7 and prior. Secunia reports several additional highly critical vulnerabilities in versions 9 and X of Reader and Acrobat. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 19, 2012.

 Android Browser: Secunia reports a less critical vulnerability in the Android browser that can be exploited to trick a user into believing he is connected to a trusted site by including the trusted site in an iframe. The vulnerability is confirmed in Browser version 2.3.3 included in Android version 2.3.3 and Browser version 3.2 included in Android version 3.2. Other versions may also be affected. Users are cautioned to not rely on displayed certificate information. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.

 AOL downloadUpdater2 Firefox Plugin: Secunia reports a highly critical vulnerability in version 1.3.0.0. Other versions may also be affected. No solution is currently available. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 12, 2012.

Apple Safari for Windows: Secunia reports a moderately critical vulnerability in Apple's Safari version 5.1.2 (7534.52.7) on Windows using the RealPlayer and Adobe Flash plug-ins. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 11, 2012.

 Apple Safari for Windows: Secunia reports a non-critical unpatched vulnerability in Safari 5.1.2. Other versions may also be affected. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 25, 2011.

 CA ARCserve Backup: Secunia reports a less critical vulnerability in CA's ARCserver Backup in versions 12.0, 12.5, 15, and 16. CA provides a partial fix solution and advises updating to a fixed version. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 25, 2012.  

 HTC Mobile Devices: The security vulnerability in the default Twitter application (Peep) in HTC products remain unpatched. Readers should refrain from using the default Twitter application (Peep). We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, February 11, 2011.

 HTC Touch2: The highly critical 0-day vulnerability in the HTC Touch2 VideoPlayer remains unpatched. Users are advised to not open files from untrusted sources. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, December 18, 2011.

 McAfee SaaS: The highly critical vulnerability in McAfee SaaS Endpoint Protection  remains unpatched. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, January 22, 2012.  

 Microsoft Windows XP: A less-critical security vulnerability has been found in Windows XP which can be exploited by malicious, local users to disclose potentially sensitive information or cause a DoS (Denial of Service). No patch is available at this time. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, August 7, 2011.

Microsoft Word: A highly critical vulnerability has been found in Microsoft Word XP and 2002. No patch is available at this time. Readers should refrain from opening untrusted files in these earlier versions of Word. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, June 19, 2011.

 Microsoft Reader: The highly critical vulnerability in Microsoft Reader, versions 2.x, remains unpatched.  Readers should refrain from opening untrusted files in Reader. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, April 15, 2011.

 PDF-Pro: Several highly critical vulnerabilities in PDF-Pro, a popular alternative to Adobe Acrobat, remain unpatched. Readers should refrain from opening untrusted files in PDF-Pro. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, March 4, 2011.

 Quick View Plus CorelDRAW: A highly critical vulnerability has been found in Quick View Plus which can be exploited by malicious people to compromise a user's system. Users should not view untrusted CDR files in Quick View Plus. We first alerted readers to this vulnerability in Weekend Vulnerability and Patch Report, July 31, 2011.

Symantec pcAnywhere:As we reported in our Cyber Security News of the Week, January 29, 2012, Symantec has confirmed that the hacker group Anonymous stole source code from the 2006 versions of several Norton security products and the pcAnywhere remote access tool. Symantec has advised users to disable pcAnywhere because of the theft of the pcAnywhere source code.

 ACD Systems: Citadel recommends users remove all ACD Systems programs from their computers. ACD Systems has failed to patch significant critical vulnerabilities in their programs dating back more than a year. Consequently Citadel recommends users remove all ACD Systems programs from their computers until the company fixes these vulnerabilities and pays proper attention to the implications of their security vulnerabilities in opening doors to cyber criminals . The community cannot tolerate a head-in-the-sand attitude, whether by developers or the people who purchase and use their programs. The consequences of willful ignorance are too grave.


If you are responsible for the security of your computer, our weekly report is for you. We strongly urge you to take action to keep your workstation patched and updated.

If someone else is responsible for the security of your computer, forward our Weekend Vulnerability and Patch Report to them and follow up to make sure your computer has been patched and updated.

Vulnerability management is a key element of cyber security management. Cyber criminals take over user computers by writing computer programs that "exploit" vulnerabilities in operating systems (Windows, Apple OS, etc) and application programs (Adobe Acrobat, Office, Flash, Java, etc). When software companies find a vulnerability, they usually issue an update patch to fix the code running in their customer's computers.

Citadel publishes our Weekend Vulnerability and Patch Report to alert readers to some of the week's important updates and vulnerabilities. Our focus is on software typically found in the small or home office (SOHO) or that users are likely to have on their home computer. The report is not intended to be a thorough listing of updates and vulnerabilities.