patch

Symantec pulls Norton patch after error reports

Symantec is providing a fix for customers who got error messages after a patch deployment went awry for some Norton users, the company said on Tuesday.

The problem started last Wednesday when Symantec deployed patches for Norton AntiVirus 2009, Norton Internet Security 2009, and Norton 360 v3 via LiveUpdate. Some customers received error messages saying that there was a problem with the Symantec Service Framework.

The patch, which is supposed to communicate with the hardware to ensure that it is correctly installed, did not handle the response from the hardware properly after it was installed, a company spokeswoman said.

The … Read more

How to heal a broken (or weakened) heart

A myocardial infarction, most commonly referred to as a heart attack, occurs when blood supply to the heart is blocked. For those who survive, permanent tissue damage is likely; during the blockage cells are literally starved to death, and do not grow back, leaving the heart forever weakened.

If only there was a way to heal a broken heart, instead of having to get an entirely new one, or undergoing a tricky bypass graft.

Enter the cardiac patch, which is essentially a tissue transplant instead of a full-on heart transplant. Using immature heart cells in newborn rats, researchers have found … Read more

Office, Windows get critical patches

Microsoft on Tuesday released nine patches, five of them critical, to plug holes in Windows and other software products.

The nine patches actually relate to 19 separate vulnerabilities in Windows, the .Net Framework, Microsoft Office, Microsoft Visual Studio, Microsoft ISA Server, Microsoft BizTalk Server, and Remote Desktop Client for Mac.

Among the issues addressed is one that Microsoft warned about last month--a vulnerability related to the Office Web Components that help users put spreadsheets, charts, and other documents onto the Web. At the time, Microsoft said it was already seeing attacks based on the flaw, which affects Office XP, … Read more

Microsoft to fix critical Windows, Office holes

Microsoft will issue fixes for five critical holes affecting Windows and a variety of other software on Patch Tuesday next week.

The critical holes, which could allow an attacker to remotely run code on a PC and take control of it, affect Windows 2000, Windows XP, Windows Vista, Windows Server 2003 and 2008, Windows Client for the Mac, Office 2000, XP and 2003, Microsoft Office Small Business Accounting 2006, Visual Studio .NET 2003, Microsoft Internet Security and Acceleration Server 2004 and 2006, and BizTalk Server 2002, according to a Microsoft security advisory released on Thursday.

Four additional vulnerabilities, rated "… Read more

Microsoft plugs critical DirectShow, Video ActiveX holes

Microsoft on Tuesday issued patches to fix critical vulnerabilities in DirectShow and Video ActiveX that have been targeted in attacks, as well as fixes for holes in Embedded OpenType Font Engine and Microsoft Publisher that could allow someone to remotely take control of the PC.

Overall, the six "Patch Tuesday" updates fix nine vulnerabilities in Windows, Microsoft Office, Internet Security and Acceleration Server, Virtual PC, and Virtual Server.

The three DirectShow vulnerabilities could allow an attacker to remotely run code on the machine if a user opened a specially crafted QuickTime file. Microsoft warned of exploits against one … Read more

DirectX targeted in Microsoft security updates

Microsoft said on Thursday that it will issue six security updates on Patch Tuesday next week, including a critical one that will fix two outstanding holes in DirectX that have been targeted in attacks.

In May, Microsoft announced that there had been attacks against a DirectX vulnerability that could allow someone to take complete control of a computer using a maliciously crafted QuickTime file.

Earlier this week, Microsoft warned of attacks being launched that exploit a hole in the Video ActiveX Control when used in Internet Explorer for recording and playing video in DirectShow. Microsoft offered a workaround on Monday … Read more

Apple: iPhone OS 3.0 plugs 46 security bugs

Apple has issued an advisory regarding security enhancements included in the iPhone OS 3.0 release Wednesday.

Here is a synopsis of the 46 iPhone security vulnerabilities addressed by the latest operating-system update for the iPhone and iPod Touch. As may be expected, many of these security patches focus on the Web-browsing framework WebKit.

CoreGraphics Changes to CoreGraphics prevent maliciously crafted image and PDF files from causing unexpected application termination or arbitrary code execution; vulnerabilities causing the same problems in FreeType v2.3.8 were also patched.

Exchange Changes were made to prevent a user from connecting to a malicious … Read more

Bookmarks, security updates for Firefox 3.0.11

Mozilla has fixed a number of security holes and made some stability improvements to the public version of Firefox. Available for Windows, Mac, and Linux, Firefox 3.0.11 also addresses a specific bug that would corrupt a user's bookmarks database.

According to the Bugzilla report, the corrupted bookmark database was the most common bug reported via Live Chat and in the Firefox support forum.

The security patches in v3.0.11 fix a hole in a JavaScript chrome execution along with other arbitrary code executions, URL spoofing, and memory corruption. The full list of security fixes can be … Read more

AOL thinks local, acquires Patch and Going

A nice little summer shopping spree for AOL: Under the auspices of new CEO Tim Armstrong, the company has acquired "hyperlocal" news site Patch and hipster-oriented events listing site Going.com.

The acquisition of Patch isn't too much of a surprise. Armstrong founded and invested in Patch while at his former gig as Google sales chief. The start-up offers a model for local news on the Web and plans to have launched in a dozen cities by the end of 2009. Going, meanwhile, has been around since 2006 and offers event and invitation services along with ticketing. … Read more

Microsoft issues patches, including one for IE exploit

Updated at 2:20 p.m. PDT with Adobe update released; at 12:25 p.m. PDT with Microsoft saying this is a record number of vulnerabilities addressed in Patch Tuesday; and at 11:45 a.m. PDT with comment.

Microsoft has released 10 security updates fixing a record number of Patch Tuesday holes, including one for a critical hole in Internet Explorer 8 that was exploited as part of a hacking contest at CanSecWest in March.

The bulletin addresses 31 vulnerabilities. "It's the most since Microsoft started releasing updates on a regular schedule of the second Tuesday … Read more