Feeds

Media Player and BEAST fix star in Patch Tuesday update

Roll up, roll up ... and upgrade already, chaps!

The Power of One eBook: Top reasons to choose HP BladeSystem

The first Patch Tuesday of 2012 rolled around with seven bulletins, including a postponed bulletin from December 2011 that plugs the BEAST SSL security flaw.

Only one of the seven vulnerabilities earns the dreaded critical rating – an update (MS12-004) that addresses two vulnerabilities in Windows Media Player: a critical bug involving MIDI playing and a lesser flaw involving closed caption (CC) interpretation. Both flaws might easily lend themselves to hacking attacks based on tricking punters into playing maliciously constructed media files.

Andrew Storms, director of security operations at nCircle, commented: "The Windows Media player bulletin for Windows Vista and XP should be the top deployment priority for everyone. The most significant bug in the bulletin can be exploited via a drive-by attacks, and that’s always a major concern.

"This bulletin provides yet another reason to upgrade to Windows 7 because those users are not affected by this drive-by exploit," he added.

The other six bulletins deal with lesser (important) security fixes. One of these updates covers a new category in security flaw – called a security feature bypass – which relates to a flaw in the Microsoft C++ .NET compiler tool that produces binary code without security protections enabled. "This seems like it could be a cause for concern, but as of yet, there isn't any evidence that shows attackers are taking advantage of the loophole,” said Storms.

Microsoft's Patch Tuesday notice is here. A graphical overview from the SANS Institute's internet Storm Centre is here.

Adobe also released its quarterly update for Adobe Acrobat and Adobe Reader on Tuesday. The software developer released a roll-up update for Adobe Acrobat/Reader 9 and X users that addresses a number of critical vulnerabilities. The cross platform update also bundles fixes for two bugs in Acrobat/Reader 9 previously patched with out-of-band fixes last year. More details in Adobe's bulletin here. ®

Boost IT visibility and business value

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NO MORE ALL CAPS and other pleasures of Visual Studio 14
Unpicking a packed preview that breaks down ASP.NET
Captain Kirk sets phaser to SLAUGHTER after trying new Facebook app
William Shatner less-than-impressed by Zuck's celebrity-only app
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Apple fanbois SCREAM as update BRICKS their Macbook Airs
Ragegasm spills over as firmware upgrade kills machines
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.