Our web Application is going to live next month!! We can't afford any security issues after launch.

e-Securitylabs's application security assessments will provide you with an objective review and analysis, ultimately providing you with the assurance that your critical application can withstand common Internet and internal threats.

I need to know the bottom line. Can someone break into my mobile!!!

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

We got hacked. Is there anyone who can help us in this situation???

e-Securitylabs helps in finding the real root cause of the issue as well as ensures that it will not happen again.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Showing posts with label Adobe. Show all posts
Showing posts with label Adobe. Show all posts

Monday, 9 July 2012

Adobe Acrobat and Reader are prone to a remote memory corruption vulnerability

Adobe Acrobat and Reader are prone to a remote memory corruption vulnerability

Release Date  2012-07-02 
Severity: High

Software: 
·         Adobe Acrobat Standard 10.1.1 and prior
 Impact  :
       ·         Denial-of-service

CVE Reference(s)
CVE-2011-4370

Description

A memory corruption vulnerability is reported in Abode Acrobat. An attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.

Solution
Update to a fixed version.

Original Advisory
Adobe:
http://www.adobe.com/support/security/bulletins/apsb12-08.html

Thursday, 5 July 2012

Adobe Flash Player Multiple Vulnerabilities

Release Date  2012-06-10 
Severity: High

Software: 
·         Adobe AIR 3.x
·         Adobe Flash Player 11.x
·         Adobe Flash Player 11.2.202.235 and earlier for Windows, Macintosh and Linux
·         Adobe Flash Player 11.1.115.8 and earlier for Android 4.x
·         Adobe Flash Player 11.1.111.9 and earlier for Android 3.x and 2.x
·         Adobe AIR 3.2.0.2070 and earlier for Windows, Macintosh and Android

 Impact  :
·         Security Bypass
·         System access

CVE Reference(s)
CVE-2012-2034
CVE-2012-2035
CVE-2012-2036
CVE-2012-2037
CVE-2012-2038
CVE-2012-2039
CVE-2012-2040

Description

Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
1) An error when parsing ActionScript can be exploited to corrupt memory.
2) An unspecified error can be exploited to cause a stack-based buffer overflow.
3) An integer overflow error can be exploited to corrupt memory.
4) An error within NPSWF32.dll when parsing certain tags can be exploited to corrupt memory.
5) An error in the "SoundMixer.computeSpectrum()" method can be exploited to bypass the same-origin policy.
6) Unspecified errors related to "null dereference" may reportedly allow code execution.
7) An unspecified error in the installer allows planting a binary file and may allow execution of arbitrary code.

Solution
Update to a fixed version.

Original Advisory
Adobe:
http://www.adobe.com/support/security/bulletins/apsb12-14.html
iDefense:

NOTE:The Information provided is on "as is" basis, without assurance of any kind.