Microsoft Word Local Machine Zone Remote Code Execution

Microsoft Word, Excel, and Powerpoint 2007 contain a remote code execution vulnerability because it is possible to reference documents such as Works document (.wps) as HTML. It will process HTML and script code in the context of the local machine zone of Internet Explorer which leads to arbitrary code execution. By persuading users into opening eg. specially crafted .WPS, “.doc “, “.RTF ” (with a space at the end) it is possible to trigger the vulnerability and run arbitrary code in the context of the logged on Windows user.

Possible Breach Results in Shutdown of Many Retail Photo Services

A potential data breach at a third-party provider has resulted in the shut down of retail photo-printing services at a number of chains, including CVS, Costco, Rite Aid, and several others. The breach reportedly hit PNI Digital Media, a Canadian company that provides the online photo platform for many retailers. The company was acquired by Staples […]

Managed Service Providers – ‘Raise Your Game’

LONDON – July 21, 2015 – AVG® Technologies N.V. (NYSE: AVG), the online security company™ for more than 200 million active users, today announced that it is the headline sponsor of the Raise Your Game roadshow series aimed at managed service providers (MSPs).

The series of events will be held at various iconic sporting locations across the United Kingdom. The full roadshow schedule takes place during the following dates in July:

  • Monday 20th – BT Murrayfield Stadium, Edinburgh
  • Tuesday 21st – St James’ Park, Newcastle
  • Wednesday 22nd – Old Trafford, Manchester
  • Thursday 23rd – Emirates Stadium, London

 

The events also sees the involvement of heavyweight industry support too. CompTIA, with more than 2,000 members and 3,000 academic and training partners that focus initiatives on supporting businesses across the full IT channel, lends its support for large and small vendors alike.

Working with a number of organisations AVG Business aims to provide value added resellers and managed services providers with an unprecedented opportunity to learn how they can achieve an efficient and profitable business.

Whether starting out or well versed in the industry, the event will help MSPs to:

  • Use vendor partnerships to meet client business needs
  • Develop and execute a go-to-market strategy to help business develop fast
  • Increase business with optimum sales and technical strategies that achieve high revenue growth

The morning sees a number of companies, including Epson, Infrascale and TigerPaw taking to the stage for presentations, informative panel discussions and Q&As on everything from upcoming trends to marketing tips before having a private stadium tour of the stadium after lunch.

All topics covered are designed to assist MSPs and the challenges they face. As such, Francois Daumard, Vice President Global Channel Sales at AVG Business will also be on hand to discuss which products and services can assist in growth opportunities, including the recently launched AVG Business Managed Workplace 9.1.

“AVG is taking this valuable opportunity to engage with MSPs as they are an integral part of our success and ongoing strategy. Events such as this really give us the opportunity to share learnings from both sides of the table so that everyone can benefit from the best solutions,” said Daumard. ”It is the perfect forum for everyone involved to network with their peers, discuss industry challenges and outline the routes to success in the future.”

 

RHSA-2015:1455-1: Important: thunderbird security update

Red Hat Enterprise Linux: An updated thunderbird package that fixes multiple security issues is now
available for Red Hat Enterprise Linux 5, 6, and 7.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-2724, CVE-2015-2725, CVE-2015-2731, CVE-2015-2734, CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739, CVE-2015-2740, CVE-2015-2741

RHSA-2015:1443-1: Important: bind security update

Red Hat Enterprise Linux: Updated bind packages that fix one security issue are now available for Red
Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-4620