Sales: 0800 321 3812
Support: 0845 680 3812

Posts Tagged ‘Update’

Apple releases security update for Safari

by: Chris Hudson
12 August, 2009

Apple have released v4.0.3 of their web browser, Safari, largely to address a number of security issues in Vista, Windows XP and Mac OS X.

This Safari 4.0.3 update is available through Apple’s Software Update system, or as a download for Mac OS X 10.4.11, 10.5.7 and 10.5.8, Mac OS X Server 10.4.11, 10.5.7 and 10.5.8, and Windows XP and Vista.

The update focuses on six problems, some critical including buffer overflows in XP and Vista that can cause crashes or arbitrary code execution and a buffer overflow in Webkit that affects both Windows and Mac and again could lead to crashes or even malicious code execution.

The update also prevents the ability to promote malicious websites into Safari’s Top Sites page, the disclosure of sensitive information, the launching of file URLs and provides fixes to the handling of look-a-like characters in domain names.

This final problem is also known as a homograph spoofing attack, where phishers may replace a Latin character in a URL with one from, say a Cyrillic alphabet, that looks visually similar to the Latin character but is actually perceived as an entirely different character by a browser. This enables phishers to register domain names that look similar to familiar brand names.

Joomla 1.5.13 security release now available

by: Chris Hudson
24 July, 2009

joomla-logo22The Joomla Project has announced the immediate availability of Joomla 1.5.13.

All designers should take note that this is a security release and the Joomla Project is advising an immediate upgrade for the popular CMS

Despite the fact that Joomla 1.5.12 was only released three weeks ago this 1.5.13 security release contains 26 bug fixes, two moderate-level security fixes and one low-level security fix!

This security release plugs a critical vulnerability in the Tiny browser (included with the TinyMCE 3.0 editor) that allowed files to be uploaded or deleted without a user needing to be logged in!

The Joomla content management system is available as part of the Fantastico package that is supplied by Intrahost in its Linux cPanel web hosting packages. Fantastico enables the automatic installation of Joomla on your web host account. You can also install Joomla manually on your web hosting account by downloading from the following links:

Download the full Joomla 1.5.13 package

Download the Joomla 1.5.13 update

Remember, if you should find a bug in Joomla 1.5 report it the 1.5 Joomla Bug Tracker.

WordPress 2.8.2 available

by: Chris Hudson
22 July, 2009

WordPress version 2.8.2 upgrade is now available; it is a security release to fix a XSS vulnerability.

Comment author URLs were not fully sanitised when displayed in the admin which could be exploited to redirect you away from the admin to another site.

To upgrade either download version 2.8.2 or automatically upgrade from the Tools->Upgrade page of your WordPress blog’s admin area.