[ISN] Secunia Weekly Summary - Issue: 2011-40

From: InfoSec News <alerts_at_private>
Date: Fri, 7 Oct 2011 02:33:54 -0500 (CDT)
========================================================================

                   The Secunia Weekly Advisory Summary
                         2011-09-29 - 2011-10-06

                        This week: 83 advisories

========================================================================
Table of Contents:

1.....................................................Word From Secunia
2....................................................This Week In Brief
3...............................This Weeks Top Ten Most Read Advisories
4................................................Secunia Community News
5................................................Secunia Corporate News
6..................................................This Week in Numbers

========================================================================
1) Word From Secunia:

An integrated and inclusive approach to highlight vulnerabilities and
their severity as they occur
According to Ovum's new technology report, companies operating diverse
and wide-ranging systems cannot solve their vulnerability management
challenges by using ad hoc tools.

The report says, "Any business that operates a range of IT-based
systems and services and regularly needs to perform vulnerability
updates and patches would benefit from the intelligence-led
vulnerability management services of the Secunia VIM product set."

Download the report here:
http://secunia.com/products/corporate/vim/ovum_2011_request/

========================================================================
2) This Week in Brief:

Multiple vulnerabilities have been reported in Google Chrome, which can
be exploited by malicious people to bypass certain security restrictions
and compromise a user's system.
http://secunia.com/advisories/46308/

Gjoko Krstic has discovered a vulnerability in Adobe Photoshop
Elements, which can be exploited by malicious people to compromise a
user's system.
http://secunia.com/advisories/46277/

Multiple vulnerabilities have been reported in Pale Moon, which can be
exploited by malicious people to bypass certain security restrictions
and compromise a user's system.
http://secunia.com/advisories/46242/

Luigi Auriemma has discovered multiple vulnerabilities in Cytel
StatXact and Cytel LogXact, which can be exploited by malicious people
to compromise a user's system.
http://secunia.com/advisories/46280/

========================================================================
3) This Weeks Top Ten Most Read Advisories:

For more information on how to receive alerts on these vulnerabilities,
subscribe to the Secunia business solutions:
http://secunia.com/advisories/business_solutions/

1.  [SA46113] Adobe Flash Player Multiple Vulnerabilities
2.  [SA46171] Mozilla Firefox Multiple Vulnerabilities
3.  [SA46203] Mozilla Firefox Multiple Vulnerabilities
4.  [SA46279] Perl Digest Module "Digest->new()" Code Injection
               Vulnerability
5.  [SA46172] Perl "decode_xs()" and "File::Glob::bsd_glob()"
               Vulnerabilities
6.  [SA45173] Sun Java JRE Insecure Executable Loading Vulnerability
7.  [SA46277] Adobe Photoshop Elements Brush / Gradient File Parsing
               Buffer Overflow
8.  [SA43157] Symantec IM Manager Multiple Vulnerabilities
9.  [SA46165] Cisco IOS Smart Install Unspecified Code Execution
               Vulnerability
10. [SA46228] IBM Tivoli Monitoring Eclipse Help Server Two
               Vulnerabilities

========================================================================
4) Secunia Community News

Help Net Security: Secunia talks patching strategies
Stefan Frei, Secunia's Research Analyst Director discusses how
organisations can ensure that they identify the right vulnerability to
patch at the right time. Read more:
http://secunia.com/company/blog_news/articles/259/

Attending RSA Conference Europe in London this year (11-13 October)?
If so, visit Secunia at stand S2 and listen to Stefan Frei, Secunia's
Research Analyst Director present "How can a CIO secure a moving target
with limited resources?" Find out more about RSA here:
http://secunia.com/resources/events/rsa_london_2011/

========================================================================
5) Secunia Corporate News

Pre-emptive action against vulnerabilities . a priority for effective
security strategies
The Secunia VIM enables you to simplify and strategize your handling of
emerging threats. Read more and request a free trial:
http://secunia.com/products/corporate/vim/

========================================================================
6) This Week in Numbers

During the past week 83 Secunia Advisories have been released. All
Secunia customers have received immediate notification on the alerts
that affect their business.

This weeks Secunia Advisories had the following spread across platforms
and criticality ratings:

Platforms:
   Windows             :     10 Secunia Advisories
   Unix/Linux          :     27 Secunia Advisories
   Other               :      3 Secunia Advisories
   Cross platform      :     43 Secunia Advisories

Criticality Ratings:
   Extremely Critical  :      0 Secunia Advisories
   Highly Critical     :     20 Secunia Advisories
   Moderately Critical :     21 Secunia Advisories
   Less Critical       :     37 Secunia Advisories
   Not Critical        :      5 Secunia Advisories

========================================================================

Secunia recommends that you verify all advisories you receive,
by clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only use
those supplied by the vendor.

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/

Subscribe:
http://secunia.com/advisories/weekly_summary/

Contact details:
Web	: http://secunia.com/
E-mail	: support_at_private
Tel	: +45 70 20 51 44
Fax	: +45 70 20 51 45


_____________________________________________________________
FINAL CALL to register #HITB2011KUL - Asia's premier
deep-knowledge network security event now in it's 9th year!
http://conference.hitb.org/hitbsecconf2011kul/
Received on Fri Oct 07 2011 - 00:33:54 PDT

This archive was generated by hypermail 2.2.0 : Fri Oct 07 2011 - 00:36:02 PDT