SecurityFocus Microsoft Newsletter #332

[email protected] 8 Mar 2007 18:42:56 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #332
----------------------------------------

This Issue is Sponsored by: Watchfire

As web applications become increasingly complex, tremendous amounts of sensitive data - personal, medical and financial - are exchanged, and stored. Consumers expect and demand security for this information. This whitepaper examines a few vulnerability detection methods - specifically comparing and contrasting manual penetration testing with automated scanning tools. Download "Automated Scanning or Manual Penetration Testing?" today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008fGD


------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Zero Day Patches
       2. Building Secure Applications: Consistent Logging
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Ipswitch IMail Server/Collaboration Suite Multiple Buffer Overflow Vulnerabilities
       2. Microsoft Windows OLE32.DLL Word Document Handling Denial Of Service Vulnerability
       3. PHP MSSQL_Connect Local Buffer Overflow Vulnerability
       4. PHP WDDX_Deserialize Buffer Overflow Vulnerability
       5. PHP PHPInfo Cross-Site Scripting Variant Vulnerability
       6. MailEnable Append Remote Buffer Overflow Vulnerability
       7. TCPDump IEEE802.11 printer Remote Buffer Overflow Vulnerability
       8. MPlayer DMO File Parsing Buffer Overflow Vulnerability
       9. Citrix Presentation Server Client Unspecified Remote Code Execution Vulnerability
       10. Adobe Acrobat/Adobe Reader Information Disclosure Vulnerability
       11. XM Easy Personal FTP Server Multiple Remote Vulnerabilities
       12. Microsoft Xbox 360 Privilege Escalation Vulnerability
       13. Nullsoft Shoutcast Logfile HTML Injection Vulnerability
       14. NetProxy Security Restriction Bypass Vulnerability
       15. Secunia Software Inspector Security Update Verification Weakness
       16. Microsoft Office Publisher Remote Denial of Service Vulnerability
       17. Microsoft Excel NULL Pointer Dereference Denial Of Service Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. MBSA alternative?
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Zero Day Patches
By Federico Biancuzzi
Zero day exploits were once the realm of just underground and elite hackers, but their increased prevalence is bringing a positive new trend: unofficial patches from members of the community, offered for protection before official vendor patches appear. Federico Biancuzzi interviewed Landon Fuller, who wrote Mac OS X patches for recent Month of Apple Bugs vulnerabilities, and the ZERT team, which has offered patches for critical Microsoft Windows zero-days that were actively exploited.
http://www.securityfocus.com/columnists/437

2. Building Secure Applications: Consistent Logging
By Rohit Sethi and Nish Bhalla
This article focuses on developers and discusses how to use consistent application-layer logging along with Log4J or Log4net for the real-time detection of attacks. 
http://www.securityfocus.com/infocus/1888


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Ipswitch IMail Server/Collaboration Suite Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 22852
Remote: Yes
Date Published: 2007-03-07
Relevant URL: http://www.securityfocus.com/bid/22852
Summary:
Ipswitch IMail Server/Collaboration Suite is prone to multiple buffer-overflow vulnerabilities because the software fails to properly check boundaries on user-supplied data before copying it to an insufficiently sized buffer.
 
Successful attacks allow arbitrary code to run, facilitating the remote compromise of affected computers. Failed exploit attempts likely cause the application to crash.

Ipswitch Collaboration 2006 Suite Premium, IMail, and IMail Plus are vulnerable to these issues.

2. Microsoft Windows OLE32.DLL Word Document Handling Denial Of Service Vulnerability
BugTraq ID: 22847
Remote: Yes
Date Published: 2007-03-06
Relevant URL: http://www.securityfocus.com/bid/22847
Summary:
The Microsoft 'ole32.dll' library is prone to a denial-of-service vulnerability. The issue occurs when the library handles document ('.doc') files containing large size values. It is conjectured that the execution of arbitrary code may be possible.
 
Software that is linked to the ole32.dll versions that reside on Microsoft Windows 2000 SP4 FR and XP SP2 FR platforms are vulnerable; other versions might alsso be affected.

3. PHP MSSQL_Connect Local Buffer Overflow Vulnerability
BugTraq ID: 22832
Remote: No
Date Published: 2007-03-06
Relevant URL: http://www.securityfocus.com/bid/22832
Summary:
PHP is prone to a local buffer-overflow vulnerability. 
 
An attacker can exploit this issue to execute arbitrary machine code in the context of the affected webserver. Failed exploit attempts will likely crash the webserver, denying service to legitimate users.  

PHP for Microsoft Windows versions prior to 4.4.6 are vulnerable; other versions may also be affected.

4. PHP WDDX_Deserialize Buffer Overflow Vulnerability
BugTraq ID: 22804
Remote: Yes
Date Published: 2007-03-04
Relevant URL: http://www.securityfocus.com/bid/22804
Summary:
PHP is prone to a remotely exploitable buffer-overflow vulnerability because it fails to properly check boundaries when processing client-supplied WDDX packets.

An attacker can exploit this issue to execute malicious code.

NOTE: This issue affects only the latest CVS release of PHP. The vulnerable code has not been released as part of an official PHP release at this time.

5. PHP PHPInfo Cross-Site Scripting Variant Vulnerability
BugTraq ID: 22803
Remote: Yes
Date Published: 2007-03-03
Relevant URL: http://www.securityfocus.com/bid/22803
Summary:
PHP is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. 

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This is a variant of the vulnerability described in BID 15428. This variant was reintroduced into PHP versions 4.4.3 through 4.4.6.

6. MailEnable Append Remote Buffer Overflow Vulnerability
BugTraq ID: 22792
Remote: Yes
Date Published: 2007-03-02
Relevant URL: http://www.securityfocus.com/bid/22792
Summary:
MailEnable is prone to a buffer-overflow vulnerability  because the application fails to properly bounds-check user-supplied data. 

An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

7. TCPDump IEEE802.11 printer Remote Buffer Overflow Vulnerability
BugTraq ID: 22772
Remote: Yes
Date Published: 2007-03-01
Relevant URL: http://www.securityfocus.com/bid/22772
Summary:
The 'tcpdump' utility is prone to a heap-based buffer-overflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.

 An attacker can exploit this issue to execute arbitrary malicious code in the context of the user running the affected application. Failed exploit attempts will likely crash the affected application.
 
This issue affects tcpdump 3.9.5 and prior versions.

8. MPlayer DMO File Parsing Buffer Overflow Vulnerability
BugTraq ID: 22771
Remote: Yes
Date Published: 2007-03-01
Relevant URL: http://www.securityfocus.com/bid/22771
Summary:
MPlayer is susceptible to a buffer-overflow vulnerability when it attempts to process malformed video files. This issue occurs because the application fails to perform proper bounds-checking on user-supplied data before copying it to an insufficiently sized memory buffer.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

MPlayer version 1.0rc1 is vulnerable to this issue; previous versions may also be affected.

9. Citrix Presentation Server Client Unspecified Remote Code Execution Vulnerability
BugTraq ID: 22762
Remote: Yes
Date Published: 2007-03-01
Relevant URL: http://www.securityfocus.com/bid/22762
Summary:
Citrix Presentation Server Client is prone to an unspecified remote code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary code within the context of the affected application. This may lead to remote unauthorized access.

All versions prior to 10.0 for Microsoft Windows platforms are vulnerable.

10. Adobe Acrobat/Adobe Reader Information Disclosure Vulnerability
BugTraq ID: 22753
Remote: Yes
Date Published: 2007-02-28
Relevant URL: http://www.securityfocus.com/bid/22753
Summary:
Adobe Acrobat and Adobe Reader may allow remote attackers to retrieve the contents of files on a vulnerable computer.  
 
Information gathered through a successful exploit of this vulnerability may aid in other attacks.

11. XM Easy Personal FTP Server Multiple Remote Vulnerabilities
BugTraq ID: 22747
Remote: Yes
Date Published: 2007-02-28
Relevant URL: http://www.securityfocus.com/bid/22747
Summary:
XM Easy Personal FTP Server is prone to multiple remote vulnerabilities, including multiple buffer-overflow issues and format-string issues.

Exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash applications, denying service to legitimate users.

Version 5.3.0 is vulnerable to these issues; other versions may also be affected.

12. Microsoft Xbox 360 Privilege Escalation Vulnerability
BugTraq ID: 22745
Remote: No
Date Published: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22745
Summary:
The Microsoft Xbox 360 is prone to a local privilege-escalation vulnerability. 

A local attacker may execute arbitrary code in 'hypervisor' mode to completely compromise a vulnerable XBox 360 gaming system.

13. Nullsoft Shoutcast Logfile HTML Injection Vulnerability
BugTraq ID: 22742
Remote: Yes
Date Published: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22742
Summary:
Nullsoft SHOUTcast is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. 

Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

This issue affects version 1.9.7 for Microsoft Windows; other versions may also be vulnerable.

14. NetProxy Security Restriction Bypass Vulnerability
BugTraq ID: 22741
Remote: Yes
Date Published: 2007-02-27
Relevant URL: http://www.securityfocus.com/bid/22741
Summary:
NetProxy is prone to a security-restriction-bypass vulnerability because the software fails to properly sanitize user-supplied input.
 
Attackers can exploit this issue to bypass the security restrictions and gain unauthorized access to restricted sites. This may allow attackers to bypass the security restrictions enforced by the application.

NetProxy version 4.03 is vulnerable; other versions may also be affected.

15. Secunia Software Inspector Security Update Verification Weakness
BugTraq ID: 22736
Remote: Yes
Date Published: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22736
Summary:
Secunia Software Inspector is prone to a weakness that provides a false sense of security to users.

Users rely on this application to provide assurance of security updates for their computers. However, this issue may cause users to be unaware of available patches for known vulnerabilities.

16. Microsoft Office Publisher Remote Denial of Service Vulnerability
BugTraq ID: 22724
Remote: Yes
Date Published: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22724
Summary:
Microsoft Office Publisher is prone to a remote denial-of-service vulnerability because the application fails to properly handle malformed files.

Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.

Microsoft Office Publisher 2007 is vulnerable; other versions may also be affected.

17. Microsoft Excel NULL Pointer Dereference Denial Of Service Vulnerability
BugTraq ID: 22717
Remote: Yes
Date Published: 2007-02-26
Relevant URL: http://www.securityfocus.com/bid/22717
Summary:
Microsoft Excel is reportedly prone to a denial-of-service vulnerability. This issue occurs when the application handles a specially crafted file. This issue stems from a NULL-pointer dereference.

Initial reports indicate that this issue is distinct from that outlined in BID 22555 Microsoft Excel Remote Denial Of Service Vulnerability.

Exploitation could cause the application to crash, resulting in a denial of service.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. MBSA alternative?
http://www.securityfocus.com/archive/88/461690

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire

As web applications become increasingly complex, tremendous amounts of sensitive data - personal, medical and financial - are exchanged, and stored. Consumers expect and demand security for this information. This whitepaper examines a few vulnerability detection methods - specifically comparing and contrasting manual penetration testing with automated scanning tools. Download "Automated Scanning or Manual Penetration Testing?" today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008fGD