Providing Free and Editor Tested Downloads

< HOME | MAC | GEEK - WEAR | SHOPPING | SUPPORT FORUM | TOP DOWNLOADS | >
MajorGeeks.com - If you thought our name was dumb, look at this slogan we got.

Admin Tools
All In One
Android
Anti-Spyware
Anti-Virus
Appearance
Back Up
Benchmarking
Bios
Browsers
CD\DVD\Blu-Ray
Covert Ops
Data Recovery
Diagnostics
Drive Cleaners
Drive Utilities
Driver Tools
Drivers
Ergonomics
Firewalls
Game Tweaks
Graphics
Input Device
Internet Tools
Mail Utilities
Memory
Messaging
Microsoft
Misc
Monitoring
Multimedia
Networking
Office Tools
ProcessManagement
Processor
Registry
Security
System Info
Toys
Video
Macintosh
Games
News Archive
- Off Base
- Way Off Base


· Facebook for Android
· Malwarebytes' Anti-Malware Database June 18, 2013
· FileZilla 3.7.1
· GoodSync 9.5.1.1
· Sun Java Runtime Environment 7 Update 25
· ArsClip 4.10
· TwInbox 2.2.0.128
· Multi Commander 3.2.0.1430
· DiskDigger 1.5.7.1537
· Bandizip 3.06

· New? Start Here
· Top Freeware Picks
· Malware Removal
· Compatibility Database
· Geektionary
· Geek Shopping
· Free Magazines
· Useful Links
· Top Freeware Picks
· Folding@Home
· About Us
· Copyright
· Privacy
· Terms Of Service
· Uninstall

There are currently 3005 user(s) online:
Google, Live Search, MSN, Yahoo

YouTube

FaceBook

Twitter

RSS / XML Feed

Pintrest



Follow @majorgeeks
· Google · Yahoo · MSN


1. K-Lite Codec Pack Update
2. IObit SmartDefrag
3. Malwarebytes Anti-Malware
4. Win7codecs
5. x64 Components
6. IObit Malware Fighter
7. JetClean
8. Windows 8 Codecs
9. SpywareBlaster
10. Iobit Driver Booster
More >>

The plane! The plane! Fantasy Island airplane used to smuggle drugs after show finished (Video)

7-Data-Recovery 3 Day Giveaway - $29.95 Value! (Updated)

What's The Best Browser to Protect You against Malware?

Man arrested for using real $50 bill

Female fan who flipped off Noah in photo identified as Filomena Tobias

Friday Photo Bombs!

NASA dumping Windows for Linux

First time setup and installation of an SSD drive

Fixing the Windows Explorer crash or freeze in Windows 7 (Updated)

Majorgeeks updates website to new CMS and design – didn’t break EVERYTHING





MajorGeeks.com » News » January 2013 » Adobe ColdFusion Exploits in Wild; Patch Remains Week Away

Adobe ColdFusion Exploits in Wild; Patch Remains Week Away


Posted on: 01/07/2013 06:17 PM [ Comments ]


Adobe is recommending ColdFusion users apply a series of mitigations to counter active exploits against vulnerabilities in the application server. An advisory was released late Friday night that the trio of flaws are being targeted by attackers, and that the company would not have a patch available for another week.

“We are in the process of finalizing a fix for the issues and expect a hotfix for ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX will be available on January 15, 2013,” the advisory said.

Two of the vulnerabilities affect ColdFusion 10, 9.0.2, 9.0.1 and 9.0. The first, CVE-2013-0625, could enable an attacker to bypass authentication in place and remotely control a ColdFusion server. CVE-2013-0629, could allow an attacker to access restricted directories on a vulnerable server.

The third vulnerability, CVE-2013-0631, affects versions 9.0.2, 9.0.1 and 9.0 and could lead to a data leak.

“Note that CVE-2013-0625 and CVE-2013-0629 only affect ColdFusion customers who do not have password protection enabled, or have no password set,” Adobe said in its advisory.

All of the vulnerabilities were given Adobe’s most critical rating.

Adobe, meanwhile, recommends a series of mitigations. The first, Adobe said, is to build credentials for Remote Development Services that are different from those used for the administrator account. Once those credentials are configured, Adobe recommends disabling RDS.

Users should also disable access from the outside to three directories: /CFIDE/administrator; /CFIDE/adminapi; and /CFIDE/componentutils, Adobe said.

Any unknown or unnecessary ColdFusion components or templates should be removed from the CFIDE or webroot directories.

Access control restrictions for the administrator interface and internal applications via the Administrator Console in version 10 should be implemented as we ll as within in the Web server’s access control mechanisms for versions 9.0.2 and earlier.

Adobe also recommends users apply the latest hotfix available for ColdFusion.








Like it? Share it....




Comments
comments powered by Disqus

« Ultra-D Technology Releases Glasses Free 4K 3D TV for Your Own Home · Adobe ColdFusion Exploits in Wild; Patch Remains Week Away · Researcher Who Found Nvidia Bug Confirms Security Update Clears Up Driver Zero Day »

MajorGeeks.com » News » January 2013 » Adobe ColdFusion Exploits in Wild; Patch Remains Week Away
© 2000-2013 MajorGeeks.com
Powered by Contentteller® Business Edition