meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, June 10th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 10 June 2016

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Google Chrome PDF Vulnerability;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, June 10th, 2016 edition of the Sandrine and Storm Center's Stormcast.

0:07.5

My name is Johannes Ulrich.

0:09.0

And today I'm recording from Baltimore, Maryland.

0:13.3

Adobe's PDF reader, of course, is often in the news for vulnerabilities,

0:17.8

typically evolving around JavaScript, Flash, or other documents being included

0:24.1

in PDFs.

0:25.6

Now back in 2014, Google included a PDF reader in Chrome.

0:33.6

That particular PDF reader was based on code developed by Fox ID.

0:40.3

Sadly, they apparently didn't get it quite right either.

0:44.3

Since Google just released an update for Chrome that fixes a vulnerability that could lead

0:50.3

to remote code execution if someone views a malicious PDF document in Google Chrome.

0:58.0

The vulnerability was found by Cisco's Talos research team and then reported to Google.

1:06.0

In order to take advantage of the vulnerability, an attacker would have to include a JPEC 2000 file

1:13.5

in a PDF document. So that's actually a little bit harder to detect than the usual JavaScript

1:20.3

or similar exploits in PDF files, for which there are a couple of relatively decent generic signatures.

1:28.3

And let's stick with Google here for a moment and in this case about Google's depreciation of SSL version 3 and RC4 support across various Google services.

1:41.3

June 16th, so next week there is another deadline looming here.

1:47.0

As of June 16th, you will no longer be able to connect to Gmail's IMAP or pop service

1:54.0

with ZSL version 3 and RC4. So if you still have an old client that uses these protocols, time to upgrade,

2:03.7

or you will lose access to Gmail, at least via IMAP and pop. This is part of a larger effort

2:11.8

by Google to get rid of SL version 3 and RC4 across all of its services and has been announced before.

2:21.3

But given that the deadline for Gmail actually comes up next week, Google sent out this reminder.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.