Tag Archives: Skype

February 2018 Update Summary

====================
Update: 28th February 2018:
Please scroll down in this post to view more recent software updates available since the original posting date of the 13th of February 2018. Thank you.
====================

Earlier today Microsoft made available their expected monthly security updates to resolve 50 vulnerabilities more formally known as CVEs (defined). As always further details are provided within Microsoft’s Security Updates Guide.

At the time of writing there are no Known Issues for this months updates.

====================

In addition to these updates; Adobe released updates for the following products:

Adobe Experience Manager (resolves 2x priority 3 CVEs)

Adobe Acrobat and Reader (priority 2, 41 CVEs)

Flash Player v28.0.0.161 (priority 1, 2 CVEs) (released on the 6th of February):

As always; you can monitor the availability of security updates for most your software from the following websites (among others) or use Secunia PSI:
—————
US Computer Emergency Readiness Team (CERT) (please see the “Information on Security Updates” heading of the “Protecting Your PC” page):

https://www.us-cert.gov/

A further useful source of update related information is the Calendar of Updates. News/announcements of updates in the categories of General SoftwareSecurity Software and Utilities are available on their website. The news/announcements are very timely and (almost always) contain useful direct download links as well as the changes/improvements made by those updates (where possible).

If you like and use it, please also consider supporting that entirely volunteer run website by donating.

====================
For this month’s Microsoft updates, I will prioritize the order of installation below. A useful list of all CVEs for this month is present here:

====================

CVE-2018-0825: StructuredQuery Remote Code Execution Vulnerability

CVE-2018-0850 and CVE-2018-0852 : Microsoft Office Outlook (separately the Office Equation Editor was disabled by this months updates to attempt to prevent further exploitation).

Microsoft Edge and Internet Explorer (multiple versions of Edge and IE affected)

====================

Please install the remaining updates at your earliest convenience.

As usual; I would recommend backing up the data on any device for which you are installing updates to prevent data loss in the rare event that any update causes unexpected issues.

Similar to last month (due to the availability of further mitigations for x86 (32 bit) version of Windows); please take extra care with your back up to ensure you can restore your systems should you wish to revert your systems prior to installing the Meltdown and Spectre patches should you wish to uninstall the Security only bundle of updates or the updates are causing your system to become unstable or to lower its performance.

Thank you.

=======================
Update: 26th February 2018
=======================
=======================
VMware Updates:
=======================
In addition to last month’s VMware updates; further security updates have been issued in February. The affected products/appliances are listed below.

Please review the above linked to security advisories and knowledge base article and apply the necessary updates and mitigation steps.

  • VMware vCloud Usage Meter (UM) 3.x
  • VMware vIdentity Manager (vIDM) 2.x and 3.x
  • VMware vCenter Server (vCSA) 5.5, 6.0 and 6.5
  • VMware vSphere Data Protection (VDP) 6.x
  • VMware vSphere Integrated Containers (VIC) 1.x
  • VMware vRealise Automation (vRA) 6.x and 7.x

=======================
Google Chrome:
=======================
This month Google made available 2 updates for Google Chrome; one in early February and the other in mid-February each resolving 1 security issue.

Google Chrome updates automatically and will apply the update the next time Chrome is closed and then re-opened. Chrome can also be updated immediately by clicking the Options button (it looks like 3 stacked small horizontal lines, sometimes called a “hamburger” button) in the upper right corner of the window and choosing “About Google Chrome” from the menu. Follow the prompt to Re-launch Chrome for the updates to take effect.
=======================

=======================
VideoLAN VLC:
=======================
On the 28th of February VideoLAN made available VLC version 3.0.1 for Linux, Windows, macOS, BSD, Android, iOS, UWP and Windows Phone. It’s release notes detail fixes for 2 security issues (use-after-free (defined) and stack buffer overflow (defined)) and a further potential security issue (out of bounds (defined) read). More than 30 other non-security issues were also resolved.

Please update to version 3.0.1 to benefit from these improvements.

In early February VideoLAN made available version 3.0 for Linux, Windows, macOS, BSD, Android, iOS, UWP and Windows Phone. While its release notes do not detail any vulnerabilities addressed it includes smashing stack protection (SSP)(defined) and high entropy ASLR (HEASLR, also previously discussed on this blog)(ASLR: defined) for 64 bit versions of VLC. If you use VLC, you may wish to update to this version to benefit from the improved performance and features it offers while also increasing security.

=======================
Skype:
=======================
Earlier this month it was reported (for example here and here) that Skype contained an important elevation of privilege (defined) security vulnerability allowing the use of DLL (defined) hijacking (defined) within its update installer.

This vulnerability required a significant volume of remediation and was not addressed within the existing 7.40 version of Skype. Microsoft subsequently issued version 8 in October to address this vulnerability. 8.16.04 is the most recent version of Skype at the time of writing.

The above referenced version is the desktop version of Skype rather than the Microsoft Store app version which will be offered for Windows 10 installations.

Windows 7 and Windows 8.1 will be offered the 8.16.04 desktop version. Updates are available from skype.com Please note; for existing 7.40 users; an automatic update prompt will not display alerting you to the presence of version 8.

If you Skype, please upgrade it to the most recent version to resolve this vulnerability.

=======================
Wireshark 2.4.5 and 2.2.13
=======================
v2.4.5: 9 CVEs (defined) resolved

v2.2.13: 8 CVEs resolved

As per standard process Linux distributions can obtain this update using the operating systems standard package manager (if the latest version is not installed automatically using the package manager you can instead compile the source code (v2.4.5) or v2.2.13). This forum thread and this forum thread may also be helpful to you with installing Wireshark on your Linux based system.

For Mac OS X and Windows, the update is available within the downloads section of the Wireshark website. In addition, a detailed FAQ for Wireshark is available here

April 2017 Security Updates Summary

As expected earlier today Microsoft and Adobe released their scheduled monthly security updates.

Microsoft’s set of updates are much lighter in volume this month addressing 45 vulnerabilities more formally known as CVEs (defined). These are detailed within Microsoft’s new Security Updates Guide.

This month sees four known issues listed for this months updates all relating to the AMD Carrizo processor experiencing an issue which prevents the installation of future Windows Updates. Microsoft states in all four knowledge base articles (listed below) they are aware of this issue and are working to resolve it in upcoming updates:

KB4015549
KB4015546
KB4015550
KB4015547

At the time of writing the IT Pro Patch Tuesday blog does not list any Known Issues (although it has not been updated since November 2016, I’m unsure why).

====================
Adobe issued five security bulletins today affecting the following products:

Adobe Campaign (1x priority 2 CVE)
Adobe Flash Player (7x priority 1 CVEs)
Adobe Acrobat and Reader (47x priority 2 CVEs)
Adobe Photoshop (2x priority 3 CVEs)
Adobe Creative Cloud Desktop (2x priority 3 CVEs)

The priority ratings are explained in this link. Depending on which version of Flash Player you have, please review the Adobe security bulletin or Microsoft bulletin as appropriate and apply the recommended updates. Google Chrome users will have the updated version installed automatically later this week.

If you use any of the above-mentioned Adobe products, please review the security bulletins linked to above and apply the necessary updates. The Flash update should be installed as soon as possible since exploit kits (defined) tend to take advantage of newly disclosed vulnerabilities very quickly.

You can monitor the availability of security updates for most your software from the following websites (among others) or use Secunia PSI:
—————
US Computer Emergency Readiness Team (CERT) (please see the “Information on Security Updates” heading of the “Protecting Your PC” page):

https://www.us-cert.gov/

A further useful source of update related information is the Calendar of Updates. News/announcements of updates in the categories of General Software, Security Software and Utilities are available on their website. The news/announcements are very timely and (almost always) contain useful direct download links as well as the changes/improvements made by those updates (where possible).

If you like and use it, please also consider supporting that entirely volunteer run website by donating.

=======================
Update: 8th May 2017:
=======================
I wish to provide information on other notable updates from April 2017 which I would recommend you install if you use these software products:

=======================
Skype: While the Skype update to version 7.34.0.102 was released in March; details of the vulnerability it addressed were not made public until April.
=======================

=======================
Putty 0.69: while released in March; it contains important security changes. It is downloadable from here.
=======================

=======================
Wireshark 2.2.6 and 2.0.12
=======================
As per standard process Linux distributions can obtain this update using the operating systems standard package manager (if the latest version is not installed automatically using the package manager you can instead compile the source code (v2.2.6) or v2.0.12). This forum thread and this forum thread may also be helpful to you with installing Wireshark on your Linux based system.

For Mac OS X and Windows, the update is available within the downloads section of the Wireshark website. In addition, a detailed FAQ for Wireshark is available here.
=======================

=======================
Oracle:
=======================
There was a record 299 vulnerabilities addressed by Oracle’s updates in April. Further details and installation steps are available here. A useful summary post from Qualys is here. Of the 299 fixes, 8 vulnerabilities were addressed in the Java runtime.

If you use any of the Oracle products listed here, please install the appropriate security updates as soon as possible.
=======================

=======================
Mozilla Firefox:
=======================
Firefox 53.0 and Firefox 53.0.2

=======================
Mozilla Firefox ESR:
=======================
Firefox ESR 45.9 and Firefox ESR 52.1.

Details of how to install updates for Firefox are here. If Firefox is your web browser of choice, please update it as soon as possible to resolve these security issues.

=======================
Google Chrome:
=======================
Google Chrome: includes 29 security fixes:

Google Chrome updates automatically and will apply the update the next time Chrome is closed and then re-opened. Chrome can also be updated immediately by clicking the Options button (it looks like 3 stacked small horizontal lines, sometimes called a “hamburger” button) in the upper right corner of the window and choosing “About Google Chrome” from the menu. Follow the prompt to Re-launch Chrome for the update to take effect.
=======================

=======================
Adobe Coldfusion:
=======================
Adobe Coldfusion: 2x priority 2 vulnerabilities resolved.

—————
If you use any of the above software, please install the appropriate updates as soon as possible. Steps for installing updates for Windows are provided on the “Protecting Your PC” page.

=======================
For the Microsoft updates this month, I will prioritize the order of installation for you below:

====================
Critical severity:
Microsoft Office and Windows WordPad (due to a previously disclosed zero day vulnerability (defined))
Microsoft Edge
Internet Explorer
Microsoft .Net Framework
====================

Install the remaining updates at your earliest convenience.

As always you can find detailed information on the contents of each security bulletin within ComputerWorld’s Patch Tuesday Debugged column.

Another security pre-caution that you may wish to take if you have Microsoft EMET (please ensure your version of EMET is the most recent version 5.52) installed is to use it to protect you from Adobe Flash being used to exploit vulnerabilities when you open a Microsoft Office document or Adobe PDF file. I provide recommendations of how to do this at the end of the July 2015 Update Summary. Please note that Microsoft EMET will be out of support on the 31st of July 2018.

As is my standard practice, I would recommend backing up the data on any device for which you are installing updates to prevent data loss in the rare event that any update causes unexpected issues.

Thank you.

Skype Resolves IP Address Disclosure Security Issue

On the 21st of January Skype corrected a vulnerability in their call/instant messenger software that could have allowed a malicious user to discover the IP address of a person of their choice using the victim’s Skype ID.

To prevent this, Skype have changed a default setting within Skype to hide your IP address from potential attackers.

Skype recommends that you install the latest of Skype to benefit from this change. An updated version will be available soon to address this for Skype when installed on an Apple iOS device.

This issue was previously discussed at length in August 2013 in a blog post by Kate Russell. Moreover further discussion of the issue addressed by Skype within this update is available within this blog post by Graham Cluley.

Thank you.

Skype Recommends Users Change Passwords

For the last 3 weeks a large number of users have been reporting spoofed messages being sent from their Skype accounts or receiving such messages. The messages are generally very short and contain shortened links to websites based in Russia possibly hosting malicious code.

In order to prevent this issue from becoming any worse, Skype have recommended that all users change their passwords by following the steps in this link.

My Skype account has not been affected by this issue but as a precaution I have changed my password. I will continue to monitor this issue and will update this post should any further recommendations be provided by Skype.

Update: 6th August 2015:
Sorry for not updating this post sooner. Skype has concluded their investigation of this issue. They have determined that user login credentials were obtained possibly using phishing attacks or when the credentials used to login into other online accounts match the credentials used for Skype.

Please find a full explanation and appropriate recommendations from Skype within the first post of this Skype forum thread. As before my account was not affected by this issue but I did change my password (as mentioned above) when this issue was first highlighted.

Update: 9th Sept 2015: Malwarebytes provides further information on this issue within their blog post.

Thank you.

Skype Releases Updates For Apple iOS, Android and Windows

Yesterday Skype released updates for the above mentioned operating systems to fix an issue that would cause Skype to crash when receiving a specific set of 8 characters within a message. Skype for Mac OS X and the Windows Store Skype app were not affected by this issue. Further details on this issue are available in this article. The updates can be downloaded from here if you are not prompted by Skype to install an update.

Installations of updates for Skype generally go smoothly. However as always, I would recommend backing up the data on any device for which you are installing updates in order to prevent data loss in the rare event that any update causes unexpected issues.

Thank you.