No Image

USN-4893-1: Firefox vulnerabilities

2021-03-26 KENNETH 0

USN-4893-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, or execute arbitrary code. (CVE-2021-23981, CVE-2021-23982, CVE-2021-23983, CVE-2021-23987, CVE-2021-23988) It was discovered that extensions could open popup windows with control of the window title in some circumstances. If a user were tricked into installing a specially crafted extension, an attacker could potentially exploit this to spook a website and trick the user into providing credentials. (CVE-2021-23984) It was discovered that the DevTools remote debugging feature could be enabled without an indication to the user. If a local attacker could modify the browser configuration, a remote attacker could potentially exploit this to obtain sensitive information. (CVE-2021-23985) It was discovered that extensions could read the response [ more… ]

No Image

Releasing Windows Feature Experience Pack 120.2212.3530.0 to the Beta & Release Preview Channels

2021-03-26 KENNETH 0

Releasing Windows Feature Experience Pack 120.2212.3530.0 to the Beta & Release Preview Channels Hello Windows Insiders, Today, we are releasing Windows Feature Experience Pack 120.2212.3530.0 to Windows Insiders in the Beta and Release Preview Channels. For Windows Insiders in the Release Preview Channel, this will be an optional update for you. NOTE: This update will NOT be offered to commercial devices in the Release Preview Channel. These devices are devices AAD-joined and/or running the Windows 10 Enterprise edition. These customers will get Windows Feature Experience Packs delivered through “C” Preview releases which then get rolled up into monthly “B” releases. This enables commercial customers to test all the non-security fixes and features that will be rolled up into the next monthly “B” release. See this blog post for the details on the existing servicing process for Windows 10. This update [ more… ]

No Image

Releasing Windows 10 Build 19043.906 (21H1) to Beta Channel

2021-03-26 KENNETH 0

Releasing Windows 10 Build 19043.906 (21H1) to Beta Channel Hello Windows Insiders, today we’re releasing 21H1 Build 19043.906 (KB5000842) to the Beta Channel for those Insiders who are on 21H1. Windows 10, version 21H1, is the next feature update for Windows 10 – read the announcement here. This update includes all the fixes in 21H1 Build 19043.899 plus the following additional fix: We fixed an issue that fails to print the graphical content in a document after installing the March 9, 2021 update. Thanks, The Windows Insider Program Team Source: Releasing Windows 10 Build 19043.906 (21H1) to Beta Channel

No Image

Releasing Windows 10 Build 19042.906 (20H2) to Release Preview Channel

2021-03-26 KENNETH 0

Releasing Windows 10 Build 19042.906 (20H2) to Release Preview Channel Hello Windows Insiders, today we’re releasing 20H2 Build 19042.906 (KB5000842) to the Release Preview Channel for those Insiders who are on 20H2 (Windows 10 October 2020 Update). This update includes the following improvements: We fixed an issue with zoom that occurs when using Microsoft Edge IE Mode on devices that use multiple high-DPI monitors. We enabled administrators to use a Group Policy to enable extended keyboard shortcuts, including Ctrl+S, for users in Microsoft Edge IE Mode. We fixed an issue that prevents the icon for a Toast collection from appearing in the Action Center if the icon file’s URI contains spaces. We fixed an issue that makes high dynamic range(HDR) screens appear much darker than expected. We fixed an issue that causes video playback to be out of sync in [ more… ]

No Image

USN-3685-2: Ruby regression

2021-03-26 KENNETH 0

USN-3685-2: Ruby regression USN-3685-1 fixed a vulnerability in Ruby. The fix for CVE-2017-0903 introduced a regression in Ruby. This update fixes the problem. Original advisory details: Some of these CVE were already addressed in previous USN: 3439-1, 3553-1, 3528-1. Here we address for the remain releases. It was discovered that Ruby incorrectly handled certain inputs. An attacker could use this to cause a buffer overrun. (CVE-2017-0898) It was discovered that Ruby incorrectly handled certain files. An attacker could use this to overwrite any file on the filesystem. (CVE-2017-0901) It was discovered that Ruby was vulnerable to a DNS hijacking vulnerability. An attacker could use this to possibly force the RubyGems client to download and install gems from a server that the attacker controls. (CVE-2017-0902) It was discovered that Ruby incorrectly handled certain YAML files. An attacker could use this to [ more… ]