buffer overflow

(get it in RSS or Atom)

Anatomy of a vulnerability - cURL web download toolkit holed by authentication bug

You may not have heard of cURL, but you've probably used software that uses it.

Recent versions contain a buffer overflow bug that could lead to remote code execution on your computer.

Paul Ducklin investigates, explains and advises...

Vulnerability reported in Foxit PDF plugin for Firefox - how to mitigate it

Italian security researcher Andrea Micalizzi has recently reported a vulnerability in the latest Foxit PDF plugin for Firefox.

Paul Ducklin examines the situation and gives a simple workaround.

Intel to eliminate zero-day threats, pigs to fly

Intel to eliminate zero-day threats, pigs to fly

According to widespread media reports, technology from Intel will soon eliminate zero-day threats. (Quite how is still a secret, but the headlines aren't mincing their words.)

This sounds good. But is it likely?

Apple fanbuoys* - let's make anti-virus peace!

qt7-sav-cool

My colleague Chet has already warned you about Apple's latest critical update to QuickTime 7, issued this morning. Chet advises you to patch as soon as possible, whether you are on Mac or Windows.

But I suspect there may be some doubters in the Mac camp.