Information Disclosure in extension "LDAP" (eu_ldap)

Release Date: September 30, 2015

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions:  version 2.8.18 and below

Vulnerability Type: Information Disclosure

Severity: Low

Suggested CVSS v2.0: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:U/RC:C (What’s that?)

Problem Description: The extension turns on PHP error output. When the ldap service is enabled in configuration for backend or frontend, PHP errors can be shown during login process, which would disclose the full server path.

Solution: Versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository. The extension author is no longer maintaining this extension. Please uninstall and delete the extension folder from your installation.

Credits: Credits go to security team member Nicole Cordes who discovered and reported the issue.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.

Arbitrary Code Execution in extension "MK Forms" (mkforms)

Release Date: September 30, 2015

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions: version 1.0.23 and below

Vulnerability Type: Arbitrary Code Execution

Severity: High

Suggested CVSS v2.0: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:O/RC:C (What’s that?)

CVE: not assigned yet

Problem Description: The extension fails to delete uploaded, invalid files which can be executed by knowing the upload folder.

Solution: An updated version 1.0.24 is available from the TYPO3 Extension Manager and at http://typo3.org/extensions/repository/download/mkforms/1.0.24/t3x/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to Hannes Bochmann who discovered and reported the issue.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.

SQL Injection in extension "http:BL Blocking" (mh_httpbl)

Release Date: September 30, 2015

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions:  version 1.1.7 and below

Vulnerability Type: SQL Injection

Severity: High

Suggested CVSS v2.0: AV:N/AC:L/Au:S/C:C/I:C/A:N/E:F/RL:U/RC:C (What’s that?)

Problem Description: Failing to properly sanitize user-supplied input, the extension is vulnerable to SQL Injection. A valid backend login with permission to access the backend module is required to exploit this vulnerability.

Solution: Versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository. The extension author failed in providing a security fix for the reported vulnerability in a decent amount of time. Please uninstall and delete the extension from your installation.

Credits: Credits go to Wouter van Dongen who discovered and reported the issue.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.

Cross-Site Request Forgery in extension "Typo3 Quixplorer" (t3quixplorer)

Release Date: September 30, 2015

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions:  version 1.7.2 and below

Vulnerability Type: Cross-Site Request Forgery

Severity: Medium

Suggested CVSS v2.0: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:F/RL:U/RC:C (What’s that?)

Problem Description: The extension fails to provide CSRF protection.

Solution: Versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository. The extension author failed in providing a security fix for the reported vulnerability in a decent amount of time. Please uninstall and delete the extension from your installation.

Note: In general the TYPO3 Security Team recommends to not use any extensions that bundle database or file management tools on production TYPO3 websites.

Credits: Credits go to Wouter van Dongen who discovered and reported the issue.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.

File Disclosure in extension "Zend Framework Integration" (zend_framework)

Release Date: September 30, 2015

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions:  version 1.7.6 and below

Vulnerability Type: File Disclosure

Severity: Medium

Suggested CVSS v2.0: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:F/RL:O/RC:C (What’s that?)

Problem Description: The extension includes a Zend Framework component which fails to sanitize user input properly. Further information can be found in the Security Advisory ZF2012-01.

Solution: An updated version 2.0.1 is available from the TYPO3 Extension Manager and at http://typo3.org/extensions/repository/download/zend_framework/2.0.1/t3x/. Users of the extension are advised to update the extension as soon as possible.

Credits: Credits go to security team member Helmut Hummel who discovered and reported the issue.

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.

AVG’s New Protection and Performance Products Press kit

Press Release

AVG Adds More Protection and Performance Features and Moves to a Continual Update Model

Blog Posts

AVG Performance PRO package is out and includes: New AVG PC TuneUp, AVG Cleaner for Mac & AVG Cleaner for Android

Reviewer’s Guides

AVG Performance – Reviewer’s Guide (PDF)
AVG Protection – Reviewer’s Guide (PDF)

Images

AVG Performance
AVG Performance screenshots
(zip)
AVG Performance icons and box shots (zip)

AVG Protection
AVG Protection screenshots (zip)
AVG Protection box shots (zip)

AVG Logo
AVG Logos – standard, horizontal and vertical  (zip)

AVG Business kicks off Cybersecurity Month with free upgrade to 2016 Business Software Suite

AMSTERDAM – September 30, 2015 – AVG® Technologies N.V. (NYSE: AVG), the online security company™ for more than 200 million monthly active users, today announced the release of its 2016 Business Edition software suite with new versions of its AVG AntiVirus Business Edition and AVG Internet Security Business Edition products. The 2016 suite, central to the company’s expanded security strategy for business, provides enterprise scale security to channel partners and small to medium-sized businesses (SMBs) in the frontline defense against malware and online threats.

Available worldwide, the products include a free remote management console to provide businesses easy and efficient remote access to all systems on a network. Technical support is also included at no cost.

“Today’s release of our core AntiVirus and Internet Security products for business delivers new and advanced cybersecurity protections and we are excited to get these into the hands of our channel and small to medium businesses across the globe,” said Joanna Brace, VP of Marketing and Product Marketing, AVG Business. “Online security is our core expertise and it is a fundamental requirement for business growth and success in today’s connected world. With the release of these critical security solutions, we are once again demonstrating our online security leadership and commitment to our customers.”

Today’s news is timed with two industry initiatives European Cyber Security Month and National Cyber Security Awareness Month, underscoring AVG’s leadership in online security and its strong commitment to protecting devices, data and people at work and at home. In support of these initiatives, channel partners will receive free upgrades to the 2016 Business Edition with renewals of existing licenses. AVG Business is also hosting security webinars for SMBs and providing comprehensive reseller kits for partners.

Features of the new 2016 Business Edition upgrade include:

  • New Scanning Engine: Scans faster and smarter with cloud-based detection technology
    The 2016 scanning engine implements AVG’s most advanced algorithms, providing better protection and shorter scanning times. It is also driven by new cloud-based detection technologies that leverage the majority of AVG’s 200 million endpoints to rapidly recognize new and emerging threats and deliver virus updates in as close to real-time as possible.
  • New Real-Time Outbreak Detection: Uses crowd intelligence technology for better protection
    Crowd intelligence technology has been added to AVG’s cloud-based outbreak detection to identify even the newest malware variants and outbreaks in software, all in real-time.
  • New Artificial Intelligence Detection: Uses advanced intelligence to identify threats
    Advanced artificial intelligence has been added to proactively identify new threats in real-time before our AVG VirusLab team has catalogued the threats.
  • Online Shield: Uses the Cloud to guard against today’s threats
    The 2016 Online Shield delivers today’s best cloud-based detection to more quickly identify dangerous downloads.
  • Data Safe: Protects your company’s most valuable data
    Data Safe lets businesses create password-protected virtual disks on their system, ensuring they can confidently encrypt and protect folders, files and data securely.
  • File Shredder: Deletes data securely
    Industry-compliant File Shredder securely deletes data to help prevent unintended recovery.

The AVG AntiVirus Business Edition and AVG Internet Security Business Edition are available now.

Channel partners can work directly with their account managers and also download our comprehensive reseller kits at our Reseller Center: https://secure.avg.com/rc-login. SMBs can purchase from the AVG.com web site: http://www.avg.com/business-security.


The AVG Business Portfolio

The AVG Business portfolio includes AVG Business CloudCare™, a free cloud-based administration platform offering channel partners a simple way to implement and manage services such as antivirus, content filtering, online backup and email security services for their customers, using centralized and highly customizable policies; the 2016 AVG Business Edition, a suite of software solutions that includes AVG AntiVirus Business Edition and AVG Internet Security Business Edition and offers comprehensive security protection for channel partners and SMBs;  AVG Business Managed Workplace, a comprehensive remote monitoring and management (RMM) platform with integrated premium remote control for channel partners and their clients; and AVG Business Secure Sign-On, a next-generation mobile device management service.

Supported by a worldwide network of more than 10,000 partners, AVG’s strong IT security heritage complements its proven strength as an RMM provider and partner to help smaller IT companies and MSPs transition and flourish as fully-fledged managed services businesses.

To view our Press Kit, which includes product screenshots, video and other elements of this news, please visit http://now.avg.com/avg-2016-business-edition-press-kit.


About AVG Technologies (NYSE: AVG)

AVG is the online security company providing leading software and services to secure devices, data and people. AVG’s award-winning technology is delivered to over 200 million monthly active users worldwide. AVG’s Consumer portfolio includes internet security, performance optimization, and personal privacy and identity protection for mobile devices and desktops. The AVG Business portfolio – delivered by managed service providers, VARs and resellers – offers IT administration, control and reporting, integrated security, and mobile device management that simplify and protect businesses.

All trademarks are the property of their respective owners.

www.avg.com


Contacts:

Zoe Kine
Tel: +1 415-694-3654
Email: [email protected]

Zena Martin
Tel: +44 7496 638 342
Email: [email protected]

 

Press information: http://now.avg.com

Cybersecurity matters

It’s unusual now to watch a newscast or read a paper and not come across a report or story of some computer security breach, theft or data or malicious program that’s wreaked havoc with a company’s, or the government’s, systems. On September 20th, the New York Times reported that Apple too is the target of malicious software in its App Store.

Tomorrow marks the start of National Cyber Security Awareness Month in the U.S. and the European Cyber Security Month. While there’s no way to insure that your business computers, devices and networks are 100% free from attack, there are a number of simple steps that businesses – even those without dedicated IT resources – can and should take to protect their business, customers and employees.

Perhaps the most important first step is to recognize that every business – even small and medium businesses – are potential targets. Hackers and distributors of malware are simply looking for any opportunity to steal information, accounts, passwords and identities. The less security they encounter, the easier their task. According to Chairman Steve Chabot (R-OH) of the Congressional Small Business Committee, “…71 percent of cyber-attacks occur at businesses with fewer than 100 employees.”

So how best can a business protect itself, particularly when it has no dedicated IT department or specific technical expertise? By deciding to implement a few easy precautions, to at least make it more difficult for hackers and others. And while our focus is business, these same suggestions work at home too and can help protect families.

  • Awareness and training – Employees should be made aware that there could be attacks and trained to recognize some of the signs of an attack or harmful email or phishing scam. Make sure that processes are in place to address requests for credit card numbers, payment information or personal data and that employees know what to do if those requests are received.
  • Password protection – Passwords are the keys to the kingdom and too often, good password policies aren’t in place or aren’t followed. Passwords should be unique, complex not obvious, and should be changed regularly. There are tools that can help manage passwords to reduce the burden.
  • Backup your data – It’s not difficult and it’s not expensive. A little discipline across all your systems will help a business recover from an attack or a catastrophic event.
  • Implement malware, spyware and firewall software solutions – This is like locking the door of a business at night. So many potential attacks can be stopped before they ever have an opportunity to steal or damage a business. Firewall, antivirus and malware software watches for possible attacks and threats and is exceptionally easy to install and manage.

Though cybersecurity month starts tomorrow, today marks the introduction of the 2016 update of the AVG Business AntiVirus and Internet Security software suite. Faster and less intrusive than ever before, these programs are that starting point for good business security.

Now is the right time to evaluate or review businesses security policies and to implement protection practices and tools if they aren’t already in place. It’s not hard to get started. The 2016 AntiVirus or Internet Security Business Editions are available at http://www.avg.com/business-security. In addition, AVG Business Partners have access to a range of resources to help establish better security and protection for clients.

Good business security doesn’t have to be overwhelming or intimidating, with the right software and by following some simple steps, all businesses can enjoy a little peace of mind.