01.08.2019 Views

Cyber Defense eMagazine August 2019

Cyber Defense eMagazine August Edition for 2019 #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cybersecurity expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group

Cyber Defense eMagazine August Edition for 2019 #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cybersecurity expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Mozilla released updates for Firefox and Firefox, ESR resolving 21 vulnerabilities and 10 vulnerabilities<br />

respectively. Both are rated as critical and include vulnerabilities that could lead to information disclosure,<br />

sandbox escapes and remote code execution.<br />

Adobe released multiple updates today for Dreamweaver, Experience Manager, Bridge CC and Flash<br />

Player. Dreamweaver and Bridge resolve a single CVE each which are rated as Important. Experience<br />

Manager resolved three vulnerabilities including one Moderate and two Important. Flash Player did not<br />

appear to include any CVEs.<br />

Oracle is releasing their Critical Patch Update next week Tuesday, so expect updates from all your<br />

favorite middleware and Java.<br />

This is a good time to bring up development tools. As the industry continues the shift toward DevOps and<br />

integrating with development binaries like Java, there are new considerations that you need to account<br />

for in managing the vulnerabilities in your environment. Java 11 changed the paradigm. There is no longer<br />

a JRE and a JDK. With Java 8 applications, a developer would build the application using the JDK and<br />

when the application was deployed to a system it required Java JRE to run. Each quarter when Oracle<br />

would release an update, the application did not require a change, but you needed to update the JRE<br />

instance to remove vulnerabilities. With Java 11, the JRE components are built right into the application.<br />

So as Oracle releases Java 11 updates resolving security vulnerabilities, a developer will need to update<br />

their version of the JDK and build the application again to include the new JRE components if any were<br />

vulnerable.<br />

Microsoft released updates for several development tools including .Net Core and ASP .Net Core this<br />

month that similarly need to update the SDK component, then build the application and redistribute to<br />

resolve the vulnerabilities. Other examples of development binaries include Apache Struts, ChakraCore,<br />

ASP.NET CORE, Open Enclave SDK and many others.<br />

About the Author<br />

Chris Goettl, is director of product management, security, Ivanti. Chris is a strong<br />

industry voice with more than 10 years of experience in supporting,<br />

implementing, and training IT Admins on how to implement strong patching<br />

processes. He hosts a monthly Patch Tuesday webinar, blogs on vulnerability<br />

and related software security topics, and his commentary is often quoted as a<br />

security expert in the media.<br />

Chris can be reached on Twitter @ChrisGoettl and at Ivanti's website:<br />

www.ivanti.com.<br />

80

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!