Stories
Slash Boxes
Comments

SoylentNews is people

posted by LaminatorX on Thursday October 16 2014, @06:32PM   Printer-friendly
from the separation-of-concerns dept.

Shaun Nichols at El Reg notes the latest Patch Tuesday

Microsoft has today patched two dozen CVE-classified security vulnerabilities in its software. People are urged to install them as soon as possible.

The US giant said the October edition of Patch Tuesday includes three critical fixes to address flaws in Internet Explorer, the .NET Framework and Windows kernel-mode driver.
[...]
MS14-061 - An 'important' rated vulnerability (CVE-2014-4117) in Office that allows an attacker to use malicious Word files to achieve remote code execution at the level of the logged-in user. The flaw can be mitigated by limiting the access rights of user accounts. The flaw is also present in Office for Mac. The discovery is credited to 35 Labs via the HP Zero Day Initiative.
[...]
And Adobe's software is still riddled with holes.

Adobe, meanwhile, has released its own monthly patch update. That patch will include a fix for three remote-code execution flaws in Flash Player for Windows, OS X, and Linux. Adobe is also patching a trio of flaws in ColdFusion allowing elevation of privilege and security control bypass.

[Update 1]: Corrected title as these vulnerabilities are not restricted to Windows.

[Update 2]: There are also reports of remote code execution and privilege elevation vulnerabilities across Solaris, Linux and Windows, via Java and Oracle: http://threatpost.com/java-reflection-api-woes-resurface-in-latest-oracle-patches/108847.

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by tibman on Friday October 17 2014, @12:42AM

    by tibman (134) on Friday October 17 2014, @12:42AM (#106858)

    I heard recently that it went the other way around.

    --
    SN won't survive on lurkers alone. Write comments.
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 2) by kaszz on Friday October 17 2014, @01:12AM

    by kaszz (4211) on Friday October 17 2014, @01:12AM (#106865) Journal

    Must be really bad then. Makes you wonder who has possessed him..