Microsoft Patch Tuesday for May 2014

This month’s crop of updates addresses thirteen vulnerabilities in Windows, Office, Internet Explorer, SharePoint and .NET.

There are eight bulletins, with two of them being flagged as Critical.

There are no updates for Windows XP this month, so it looks like Microsoft really has put the final nail in XP’s coffin.

The summary bulletin on the TechNet Security TechCenter has all the gory details. As usual, there’s a friendlier summary on the MSRC blog. The SANS Handler’s Blog has a slightly different take on this month’s updates.

Firefox 29.0.1 released

On May 9, a new version of Firefox was released by Mozilla. Since version 29.0.1 is considered a minor (‘dot’) release, there was no formal announcement.

The release notes provide some clues as to the changes in 29.0.1. A few minor bugs were fixed, but none of them appear to be security-related. The colour of unselected tabs was changed to make them more visible than they are in Firefox 29.

Advance notification for May 2014 Patch Tuesday

Next Tuesday we’ll find out whether Microsoft is going to stick to its original plan and stop providing Windows XP security updates to us ordinary folks.

According to the Advance Notification post on the MSRC blog, this month’s updates will include eight bulletins, with two of those being Critical. The updates affect the usual suspects, including Windows, Office, Internet Explorer and .NET.

The more technical Advance Notification security bulletin on the TechNet Security Tech Center blog definitely does not list Windows XP anywhere.

DropBox issue exposes private documents

Security researchers recently discovered a flaw in DropBox that could allow access to users’ private documents in certain circumstances. DropBox responded quickly to fix the vulnerability. It’s not clear whether the vulnerability was known to – or exploited by – any nefarious persons.

If you use DropBox, you should review your Shared Links settings and restrict shared links to collaborators only.

Opera 21

The latest Webkit-based Opera is version 21.0.1432.57. There’s nothing much of interest in this new version, with the major change being the use of ‘Aura’, an improved desktop window manager that’s also part of the toolkit used by Google for its Chromium O/S and Chrome web browser.

There’s still no sidebar, which makes one wonder whether Opera will ever recover its former full-featured glory. The developers keep insisting that they will add missing features back to the browser, but if they’re pushing out major releases with nothing changed except a slightly faster user interface, it seems they are concentrating on the wrong things.

There are apparently no security fixes in this version.

Rants and musings on topics of interest. Sometimes about Windows, Linux, security and cool software.