Vendors/Products - Page 35
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
Thanks to Andreas Fabis for sending this in to us. atsec information security is pleased to announce the successful Common Criteria Certification of Red Hat Enterprise Linux Version 5.3 at EAL 4 (augmented for flaw remediation) with the Controlled Access Protection Profile (CAPP). Under Common Criteria, products are evaluated against strict standards for various features, including security functionality, development environment, security vulnerability handling, documentation of security-related topics, and product testing.
The Apache HTTP Server developers have released version 1.3.42 of the popular web server, noting that this will be the last update for the 1.3 series. The release of 1.3.42 is a bug fix and security release, with one moderate security flaw in mod_proxy fixed by preventing integer overflow on platforms where the size of an integer variable in memory was less than that of a long variable.
The recession continues to be no barrier to acquisitions with the news that PGP Corporation has reached into its pockets to buy German encryption services company TC TrustCenter. As usual, because the companies involved, including TC TrustCenter's US parent ChosenSecurity, are private, the sums involved has not been made public. The 75-person TC TrustCenter will continue as a division of PGP, however, with its own head and retaining its own branding.
VMware has advised of a number of vulnerabilities in several of its products, including ESX, Server, VirtualCenter and vCenter. According to the company, a number of the issues relate to problems in the Java Runtime Environment (JRE) and several of the 47 vulnerabilities can be used by an attacker to compromise a system.
Google is touting three new security features added to the latest version of its Chrome browser, including new protections against reflective cross-site scripting. Google has beefed up the latest version of its Chrome browser with new security protections designed to help developers build secure Websites.
Cisco, NetApp and VMware announced a project to improve the security of virtualization deployments, with a focus on isolating applications that use the same physical network, server and storage resources in multi-tenant systems.
-Trusted Computer Solutions (TCS), a leading developer of cross domain and cyber security solutions, today announced that its widely adopted automated Operating System (OS) hardening tool, Security Blanket, now supports Novell SUSE as well as openSUSE and Fedora 11. The product already supports Red Hat Enterprise Linux, Solaris, and Oracle Enterprise Linux. This new version of Security Blanket also provides role-based access control (RBAC) and a JAVA-based administration console. By providing such broad OS support TCS is expanding its market reach into new U.S. verticals and into Europe.
Security vendor Websense if offering Facebook users and businesses a new free
Mozilla yesterday reported a "huge increase" in downloads of Firefox in Germany after that country's computer security agency urged users of Microsoft's Internet Explorer (IE) to dump the browser and run a rival instead.
An update for the MIT's Kerberos 5 implementation fixes a null-pointer dereference vulnerability that allows attackers to remotely crash the Key Distribution Center (KDC). According to an advisory by the MIT, sending a specially crafted client request to the KDC is all that is required to exploit the vulnerability.
Version 8.14.4 of Sendmail, the open source mail transfer agent (MTA), includes fixes for several security vulnerabilities including some integer overflows, memory leaks and for the SSL NUL character problem disclosed in mid 2009. The release also corrects a resolution error where an apparently valid host name lookup contained a NULL pointer; this problem caused crashes on some Linux versions of the software. The update also includes a number of corrections for several non-security issues.
The Apache SpamAssassin spam filter has been shipping with a rule which defined any year past 2009 as "grossly in the future" and adding 3.2 to the email's spam score. The default threshold for spam is 5.0, so the error makes it much more likely that legitimate mail will be falsely marked as spam.
Fact: Everyone who patches is safer. Fact: Not everyone patches. The gap between the two facts is too deep for even security experts to explain, although they try, with theories running from the conspiratorial -- pirates hate to patch, they say, because they're afraid vendors, Microsoft mostly, will spy them out -- to the prosaic ... that people are, by nature, just lazy.
Programs with known security vulnerabilities are currently one of the biggest security problems; many Windows PCs contain old versions of programs such as Java, Adobe Reader or Flash or are missing critical Windows updates. Such computers are easy prey for cyber criminals because simply visiting a crafted web page may be sufficient for infection with unseen malicious software that could spy on passwords and online banking transactions.
About a year after it first appeared as a Windows application, Google's Chrome browser is finally available in beta for Linux. Google had to limit its compatible distro list to a handful of popular Linux versions, but those who can use it will likely enjoy its speed, features and the hundreds of extensions Google has made available.
The Mozilla developers have released version 3.5.6 of their open source Firefox web browser to address a total of seven vulnerabilities, three of them critical. According to Mozilla, the release "is a short-cycle security and sustained engineering release to fix several top crashing bugs".
Adobe's Flash Player software is on 99 percent of Internet-connected desktops, offering up multimedia and video capabilities on a multitude of popular Web sites such as YouTube. But the Adobe Flash platform has been beset by a rash of security problems that give intruders potential access to computers running the software.
Microsoft said Wednesday it has reposted a tool to the Internet that aids installing Windows 7 on Netbooks and computers without an optical drive. The software maker pulled the Windows 7 USB/DVD Download tool off its Web site last month after it was pointed out that the software appeared to use open-source code licensed under the GNU Public License (GPL v2). Microsoft later apologized and said that the code did in fact use GPL code.
Google's new cloud-based Chromium operating system, slated to debut in the second half of 2010, may not immediately change the way attacks are carried out, but if the OS is successful in gaining broad adoption, it could have a far-reaching impact in the way security is deployed, says a group of Web security experts.
An Israeli mobile security firm that a month ago offered $100,000 in gold to anyone who could hack its voice encryption technology has upped the ante to $250,000. Gold Lock posted a sample of an encrypted voice conversation on its Website and is offering the golden reward to any hackers who can crack it and send the company a transcript of the call.