SecurityFocus Microsoft Newsletter #345

[email protected] 6 Jun 2007 23:54:01 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #345
----------------------------------------

This Issue is Sponsored by: Norwich University

Norwich University's Master of Science in Information Assurance Program c=
ompliments the skills of information security professionals while prepari=
ng them to take on management roles in an organization-wide information s=
ecurity program, such as Chief Security Officers, Security Administrators=
 and Chief Information Security Officers. This 18 month program is conven=
iently delivered online and is accredited by The National Security Agency=
 and Department of Homeland Security as a "Center for Academic Excellence=
 in Information Assurance Education"

For more information, visit http://www.msia.norwich.edu/msec


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Security Analogies
       2. Your Space, My Space, Everybody's Space
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Computer Associates ARCserve Backup Multiple Unspecified Remote=
 Buffer Overflow Vulnerabilities
       2. Microsoft Windows GDI+ ICO File Remote Denial of Service Vulner=
ability
       3. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vul=
nerabilities
       4. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
       5. Mozilla Firefox Beatnik Extension Remote Script Code Execution =
Vulnerability
       6. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vuln=
erability
       7. Mozilla Firefox Resource Variant Directory Traversal Vulnerabil=
ity
       8. Microsoft Internet Explorer Location Object Webpage Spoofing Vu=
lnerability
       9. SNMPC Username/Password Remote Denial of Service Vulnerability
       10. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vu=
lnerability
       11. Microsoft Internet Explorer Javascript Cross Domain Informatio=
n Disclosure Vulnerability
       12. DVD X Player PLF File Buffer Overflow Vulnerability
       13. Microsoft Active Directory Logon Hours Username Enumeration We=
akness
       14. Acoustica MP3 CD Burner PlayList Files Buffer Overflow Vulnera=
bility
       15. Avira Antivir Tar Archive Handling Remote Denial Of Service Vu=
lnerability
       16. F-Secure Multiple Products Real-time Scanning Component Local =
Privilege Escalation Vulnerability
       17. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerabili=
ty
       18. EDraw Office Viewer Component ActiveX Control Arbitrary File D=
elete Vulnerability
       19. EDraw Office Viewer Component EDrawOfficeViewer.OCX ActiveX Co=
ntrol Buffer Overflow Vulnerability
       20. Zenturi ProgramChecker SASATL.DLL ActiveX Control Multiple Buf=
fer Overflow Vulnerabilities
       21. Microsoft DirectX Media DXTMSFT.DLL ActiveX Control Denial of =
Service Vulnerability
       22. Avira Antivir Antivirus Multiple Remote Vulnerabilities
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #344
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Security Analogies
By Scott Granneman
Scott Granneman discusses security analogies and their function in educat=
ing the masses on security concepts.
http://www.securityfocus.com/columnists/445

2. Your Space, My Space, Everybody's Space
By Mark Rasch
Privacy is about protecting data when somebody wants it for some purpose.=
 It is easy to protect data that nobody wants.
http://www.securityfocus.com/columnists/444


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Computer Associates ARCserve Backup Multiple Unspecified Remote Buffer=
 Overflow Vulnerabilities
BugTraq ID: 24348
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24348
Summary:
Computer Associates ARCserve Backup for Laptops & Desktops is prone to mu=
ltiple unspecified remote buffer-overflow vulnerabilities. These issues o=
ccur because the application fails to bounds-check user-supplied input be=
fore copying it into an insufficiently sized memory buffer.

No further details are currently available. We will update this BID as mo=
re information emerges.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with SYSTEM-Level privileges. This will result in a=
 complete compromise of affected computers.

ARCserve Backup for Laptops & Desktops r11.1 is reported vulnerable.

2. Microsoft Windows GDI+ ICO File Remote Denial of Service Vulnerability
BugTraq ID: 24346
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24346
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause it fails to properly handle maliciously crafted ICO files.

An attacker may exploit this issue by enticing victims into opening a mal=
icious file.

Successful exploits will result in denial-of-service conditions on applic=
ations using the affected library. Applications such as Windows Explorer =
or Picture and Fax viewer have been identified as vulnerable.

3. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vulnerabil=
ities
BugTraq ID: 24341
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24341
Summary:
Yahoo! Messenger is prone to multiple unspecified remote code-execution v=
ulnerabilities.

No further information is currently available. This BID will be updated a=
s more information is disclosed.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of the affected application. This fa=
cilitates the remote compromise of affected computers.

Specific vulnerable Yahoo! Messenger versions are not known, but versions=
 in the 8 series for Microsoft Windows are reportedly affected.

4. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
BugTraq ID: 24339
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24339
Summary:
MPlayer is prone to multiple buffer-overflow vulnerabilities when it atte=
mpts to process malformed album and category titles. These issues occur b=
ecause the application fails to perform proper bounds-checking on user-su=
pplied data before copying it to an insufficiently sized memory buffer.

An attacker may exploit these issues to execute arbitrary code with the p=
rivileges of the user that activated the vulnerable application. This may=
 facilitate unauthorized access or privilege escalation.

MPlayer 1.0rc1 is vulnerable to these issues; other versions may also be =
affected.

5. Mozilla Firefox Beatnik Extension Remote Script Code Execution Vulnera=
bility
BugTraq ID: 24324
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24324
Summary:
A remote code-execution vulnerability affects the Beatnik extension for M=
ozilla Firefox because the application fails to validate input errors whe=
n processing RSS feeds.
=20
An attacker may leverage this issue to execute arbitrary code in the cont=
ext of the user account running the affected extension. This may facilita=
te cross-site scripting as well as a compromise of an affected computer.

Beatnik 1.0 is vulnerable; other versions may also be affected.

6. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vulnerabili=
ty
BugTraq ID: 24316
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24316
Summary:
ClamAV is prone to a denial-of-service vulnerability when handling malfor=
med OLE2 files.

A successful attack may allow an attacker to cause denial-of-service cond=
itions.
=20
Versions prior to ClamAV 0.90.3 are affected.

7. Mozilla Firefox Resource Variant Directory Traversal Vulnerability
BugTraq ID: 24303
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24303
Summary:
Mozilla Firefox is prone to a directory-traversal vulnerability because i=
t fails to adequately sanitize user-supplied data.

An attacker can exploit this issue to access arbitrary files on an unsusp=
ecting user's computer. Successful exploits can expose potentially sensit=
ive information that could aid in further attacks.

This issue was introduced as part of the fix for BID 24191 (Mozilla Firef=
ox Resource Directory Traversal Vulnerability) in Firefox 2.0.0.4.

8. Microsoft Internet Explorer Location Object Webpage Spoofing Vulnerabi=
lity
BugTraq ID: 24298
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24298
Summary:
Microsoft Internet Explorer is prone to a webpage-spoofing vulnerability.

Attackers may exploit this vulnerability via a malicious webpage to spoof=
 the contents and origin of a page that the victim may trust. Attackers m=
ay find this issue useful in phishing or other attacks that rely on conte=
nt spoofing.

9. SNMPC Username/Password Remote Denial of Service Vulnerability
BugTraq ID: 24292
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24292
Summary:
SNMPc is prone to a remote denial-of-service vulnerability.

Successfully exploiting this issue would cause the affected application t=
o crash, denying service to legitimate users.=20

This issue is reported to affect versions of SNMPc prior to 7.0.19.

10. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 24289
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24289
Summary:
ClamAV is prone to a denial-of-service vulnerability.

A successful attack may allow an attacker to cause denial-of-service cond=
itions.

11. Microsoft Internet Explorer Javascript Cross Domain Information Discl=
osure Vulnerability
BugTraq ID: 24283
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24283
Summary:
The browser is prone to a cross-domain information-disclosure vulnerabili=
ty because scripts may persist across navigations.

This vulnerability may let a malicious site interact with a site in an ar=
bitrary external domain. Attackers could exploit this to gain access to s=
ensitive information that is associated with the external domain. Other a=
ttacks may be possible, such as executing script code in other browser se=
curity zones.

UPDATE: Reports indicate that Safari browser may also be vulnerable, but =
this has not been confirmed.

UPDATE (June 6, 2007): The WebKit framework used by Safari is reported vu=
lnerable. Builds 522 and later, which are associated with the nightly Web=
Kit build, are vulnerable; other versions may also be affected.

12. DVD X Player PLF File Buffer Overflow Vulnerability
BugTraq ID: 24278
Remote: Yes
Date Published: 2007-06-02
Relevant URL: http://www.securityfocus.com/bid/24278
Summary:
DVD X Player is prone to a buffer-overflow vulnerability because the appl=
ication fails to bounds-check user-supplied data before copying it into a=
n insufficiently sized buffer.=20

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected user. Failed exploit a=
ttempts likely result in application crashes.

This issue affects DVD X Player 4.1; other versions may also be affected.

13. Microsoft Active Directory Logon Hours Username Enumeration Weakness
BugTraq ID: 24248
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24248
Summary:
Microsoft Active Directory is prone to a username-enumeration weakness be=
cause of a design error in the application when verifying user-supplied i=
nput.

Attackers may exploit this weakness to discern valid usernames. This may =
aid them in brute-force password cracking or other attacks.

Microsoft Active Directory on Microsoft Windows Server 2003 Standard Edit=
ion is vulnerable; other versions may also be affected.

14. Acoustica MP3 CD Burner PlayList Files Buffer Overflow Vulnerability
BugTraq ID: 24247
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24247
Summary:
Acoustica MP3 CD Burner is prone to a a buffer-overflow vulnerability bec=
ause the application fails to bounds-check user-supplied data before copy=
ing it into an insufficiently sized buffer.=20

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected user. Failed exploit a=
ttempts likely result in application crashes.

15. Avira Antivir Tar Archive Handling Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 24239
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24239
Summary:
Avira Antivir is prone to a denial-of-service vulnerability because the a=
pplication fails to handle certain TAR archives.

 Remote attackers may exploit this issue by enticing victims into opening=
 maliciously crafted TAR archives.

A successful attack may allow attackers to cause denial-of-service condit=
ions.

16. F-Secure Multiple Products Real-time Scanning Component Local Privile=
ge Escalation Vulnerability
BugTraq ID: 24237
Remote: No
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24237
Summary:
Multiple F-Secure workstation and file-server products are prone to a loc=
al privilege-escalation vulnerability.
=20
Exploiting this vulnerability allows local attackers to gain superuser or=
 SYSTEM-level privileges, leading to a complete compromise of the affecte=
d computer.

17. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerability
BugTraq ID: 24235
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24235
Summary:
Multiple F-Secure Anti-Virus applications are prone to a buffer-overflow =
vulnerability when they process certain LHA archive files. This issue occ=
urs because the applications fail to properly check boundaries on user-su=
pplied data before copying it to an insufficiently sized memory buffer.

Successful exploits can allow attackers to execute arbitrary code with th=
e privileges of the vulnerable application. Failed exploit attempts will =
likely result in denial-of-service conditions.

Reports indicate that this vulnerability also occurs when processing malf=
ormed LZH archives, ARJ files, and FSG packed files.

18. EDraw Office Viewer Component ActiveX Control Arbitrary File Delete V=
ulnerability
BugTraq ID: 24230
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24230
Summary:
The EDraw Office Viewer Component ActiveX Control is prone to an arbitrar=
y-file-delete vulnerability.=20

An attacker can exploit this issue to delete arbitrary files on the affec=
ted computer. Successful attacks can result in denial-of-service conditio=
ns.

19. EDraw Office Viewer Component EDrawOfficeViewer.OCX ActiveX Control B=
uffer Overflow Vulnerability
BugTraq ID: 24229
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24229
Summary:
EDraw Office Viewer Component ActiveX control is prone to a buffer-overfl=
ow vulnerability because it fails to bounds-check user-supplied data befo=
re copying it into an insufficiently sized buffer.

An attacker can exploit this issue to cause a denial-of-service condition=
. Arbitrary code execution may be possible, but has not been confirmed.=20

This issue affects EDraw Office Viewer Component 4.0.5.20; other versions=
 may also be affected.

20. Zenturi ProgramChecker SASATL.DLL ActiveX Control Multiple Buffer Ove=
rflow Vulnerabilities
BugTraq ID: 24217
Remote: Yes
Date Published: 2007-05-29
Relevant URL: http://www.securityfocus.com/bid/24217
Summary:
Several Zenturi ProgramChecker ActiveX controls are prone to multiple buf=
fer-overflow vulnerabilities because they fail to bounds-check user-suppl=
ied data before copying it into an insufficiently sized buffer.

Successfully exploiting these issues allow remote attackers to execute ar=
bitrary code in the context of the application using the ActiveX control =
(typically Internet Explorer). Failed exploit attempts likely result in d=
enial-of-service conditions.

21. Microsoft DirectX Media DXTMSFT.DLL ActiveX Control Denial of Service=
 Vulnerability
BugTraq ID: 24188
Remote: Yes
Date Published: 2007-05-28
Relevant URL: http://www.securityfocus.com/bid/24188
Summary:
Microsoft DirectX Media ActiveX control is prone to a denial-of-service v=
ulnerability because it fails to perform adequate checks on user-supplied=
 data.

Successfully exploiting this issue allows remote attackers  to crash appl=
ications using the affected ActiveX control (typically Internet Explorer)=
. Given the nature of this issue, remote code execution may be possible, =
but this has not been confirmed.

22. Avira Antivir Antivirus Multiple Remote Vulnerabilities
BugTraq ID: 24187
Remote: Yes
Date Published: 2007-05-28
Relevant URL: http://www.securityfocus.com/bid/24187
Summary:
Avira Antivir Antivirus is prone to multiple remote vulnerabilities.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with elevated privileges, facilitating the complete=
 compromise of affected computers. Attackers may also trigger denial-of-s=
ervice conditions by crashing the application or causing infinite loops.

These issues affect:

Avira Antivir AVPack versions prior to 7.03.00.09
Engine versions prior to 7.04.00.24

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #344
http://www.securityfocus.com/archive/88/470135

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Norwich University

Norwich University's Master of Science in Information Assurance Program c=
ompliments the skills of information security professionals while prepari=
ng them to take on management roles in an organization-wide information s=
ecurity program, such as Chief Security Officers, Security Administrators=
 and Chief Information Security Officers. This 18 month program is conven=
iently delivered online and is accredited by The National Security Agency=
 and Department of Homeland Security as a "Center for Academic Excellence=
 in Information Assurance Education"

For more information, visit http://www.msia.norwich.edu/msec