SecurityFocus Microsoft Newsletter #345
[email protected] 6 Jun 2007 23:54:01 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #345
----------------------------------------
This Issue is Sponsored by: Norwich University
Norwich University's Master of Science in Information Assurance Program c=
ompliments the skills of information security professionals while prepari=
ng them to take on management roles in an organization-wide information s=
ecurity program, such as Chief Security Officers, Security Administrators=
and Chief Information Security Officers. This 18 month program is conven=
iently delivered online and is accredited by The National Security Agency=
and Department of Homeland Security as a "Center for Academic Excellence=
in Information Assurance Education"
For more information, visit http://www.msia.norwich.edu/msec
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Security Analogies
2. Your Space, My Space, Everybody's Space
II. MICROSOFT VULNERABILITY SUMMARY
1. Computer Associates ARCserve Backup Multiple Unspecified Remote=
Buffer Overflow Vulnerabilities
2. Microsoft Windows GDI+ ICO File Remote Denial of Service Vulner=
ability
3. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vul=
nerabilities
4. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
5. Mozilla Firefox Beatnik Extension Remote Script Code Execution =
Vulnerability
6. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vuln=
erability
7. Mozilla Firefox Resource Variant Directory Traversal Vulnerabil=
ity
8. Microsoft Internet Explorer Location Object Webpage Spoofing Vu=
lnerability
9. SNMPC Username/Password Remote Denial of Service Vulnerability
10. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vu=
lnerability
11. Microsoft Internet Explorer Javascript Cross Domain Informatio=
n Disclosure Vulnerability
12. DVD X Player PLF File Buffer Overflow Vulnerability
13. Microsoft Active Directory Logon Hours Username Enumeration We=
akness
14. Acoustica MP3 CD Burner PlayList Files Buffer Overflow Vulnera=
bility
15. Avira Antivir Tar Archive Handling Remote Denial Of Service Vu=
lnerability
16. F-Secure Multiple Products Real-time Scanning Component Local =
Privilege Escalation Vulnerability
17. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerabili=
ty
18. EDraw Office Viewer Component ActiveX Control Arbitrary File D=
elete Vulnerability
19. EDraw Office Viewer Component EDrawOfficeViewer.OCX ActiveX Co=
ntrol Buffer Overflow Vulnerability
20. Zenturi ProgramChecker SASATL.DLL ActiveX Control Multiple Buf=
fer Overflow Vulnerabilities
21. Microsoft DirectX Media DXTMSFT.DLL ActiveX Control Denial of =
Service Vulnerability
22. Avira Antivir Antivirus Multiple Remote Vulnerabilities
III. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #344
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Security Analogies
By Scott Granneman
Scott Granneman discusses security analogies and their function in educat=
ing the masses on security concepts.
http://www.securityfocus.com/columnists/445
2. Your Space, My Space, Everybody's Space
By Mark Rasch
Privacy is about protecting data when somebody wants it for some purpose.=
It is easy to protect data that nobody wants.
http://www.securityfocus.com/columnists/444
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Computer Associates ARCserve Backup Multiple Unspecified Remote Buffer=
Overflow Vulnerabilities
BugTraq ID: 24348
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24348
Summary:
Computer Associates ARCserve Backup for Laptops & Desktops is prone to mu=
ltiple unspecified remote buffer-overflow vulnerabilities. These issues o=
ccur because the application fails to bounds-check user-supplied input be=
fore copying it into an insufficiently sized memory buffer.
No further details are currently available. We will update this BID as mo=
re information emerges.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with SYSTEM-Level privileges. This will result in a=
complete compromise of affected computers.
ARCserve Backup for Laptops & Desktops r11.1 is reported vulnerable.
2. Microsoft Windows GDI+ ICO File Remote Denial of Service Vulnerability
BugTraq ID: 24346
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24346
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause it fails to properly handle maliciously crafted ICO files.
An attacker may exploit this issue by enticing victims into opening a mal=
icious file.
Successful exploits will result in denial-of-service conditions on applic=
ations using the affected library. Applications such as Windows Explorer =
or Picture and Fax viewer have been identified as vulnerable.
3. Yahoo! Messenger Multiple Unspecified Remote Code Execution Vulnerabil=
ities
BugTraq ID: 24341
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24341
Summary:
Yahoo! Messenger is prone to multiple unspecified remote code-execution v=
ulnerabilities.
No further information is currently available. This BID will be updated a=
s more information is disclosed.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of the affected application. This fa=
cilitates the remote compromise of affected computers.
Specific vulnerable Yahoo! Messenger versions are not known, but versions=
in the 8 series for Microsoft Windows are reportedly affected.
4. MPlayer Multiple CDDB Parsing Buffer Overflow Vulnerabilities
BugTraq ID: 24339
Remote: Yes
Date Published: 2007-06-06
Relevant URL: http://www.securityfocus.com/bid/24339
Summary:
MPlayer is prone to multiple buffer-overflow vulnerabilities when it atte=
mpts to process malformed album and category titles. These issues occur b=
ecause the application fails to perform proper bounds-checking on user-su=
pplied data before copying it to an insufficiently sized memory buffer.
An attacker may exploit these issues to execute arbitrary code with the p=
rivileges of the user that activated the vulnerable application. This may=
facilitate unauthorized access or privilege escalation.
MPlayer 1.0rc1 is vulnerable to these issues; other versions may also be =
affected.
5. Mozilla Firefox Beatnik Extension Remote Script Code Execution Vulnera=
bility
BugTraq ID: 24324
Remote: Yes
Date Published: 2007-06-05
Relevant URL: http://www.securityfocus.com/bid/24324
Summary:
A remote code-execution vulnerability affects the Beatnik extension for M=
ozilla Firefox because the application fails to validate input errors whe=
n processing RSS feeds.
=20
An attacker may leverage this issue to execute arbitrary code in the cont=
ext of the user account running the affected extension. This may facilita=
te cross-site scripting as well as a compromise of an affected computer.
Beatnik 1.0 is vulnerable; other versions may also be affected.
6. Clam AntiVirus ClamAV OLE2 Parser Remote Denial Of Service Vulnerabili=
ty
BugTraq ID: 24316
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24316
Summary:
ClamAV is prone to a denial-of-service vulnerability when handling malfor=
med OLE2 files.
A successful attack may allow an attacker to cause denial-of-service cond=
itions.
=20
Versions prior to ClamAV 0.90.3 are affected.
7. Mozilla Firefox Resource Variant Directory Traversal Vulnerability
BugTraq ID: 24303
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24303
Summary:
Mozilla Firefox is prone to a directory-traversal vulnerability because i=
t fails to adequately sanitize user-supplied data.
An attacker can exploit this issue to access arbitrary files on an unsusp=
ecting user's computer. Successful exploits can expose potentially sensit=
ive information that could aid in further attacks.
This issue was introduced as part of the fix for BID 24191 (Mozilla Firef=
ox Resource Directory Traversal Vulnerability) in Firefox 2.0.0.4.
8. Microsoft Internet Explorer Location Object Webpage Spoofing Vulnerabi=
lity
BugTraq ID: 24298
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24298
Summary:
Microsoft Internet Explorer is prone to a webpage-spoofing vulnerability.
Attackers may exploit this vulnerability via a malicious webpage to spoof=
the contents and origin of a page that the victim may trust. Attackers m=
ay find this issue useful in phishing or other attacks that rely on conte=
nt spoofing.
9. SNMPC Username/Password Remote Denial of Service Vulnerability
BugTraq ID: 24292
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24292
Summary:
SNMPc is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue would cause the affected application t=
o crash, denying service to legitimate users.=20
This issue is reported to affect versions of SNMPc prior to 7.0.19.
10. Clam AntiVirus ClamAV RAR Handling Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 24289
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24289
Summary:
ClamAV is prone to a denial-of-service vulnerability.
A successful attack may allow an attacker to cause denial-of-service cond=
itions.
11. Microsoft Internet Explorer Javascript Cross Domain Information Discl=
osure Vulnerability
BugTraq ID: 24283
Remote: Yes
Date Published: 2007-06-04
Relevant URL: http://www.securityfocus.com/bid/24283
Summary:
The browser is prone to a cross-domain information-disclosure vulnerabili=
ty because scripts may persist across navigations.
This vulnerability may let a malicious site interact with a site in an ar=
bitrary external domain. Attackers could exploit this to gain access to s=
ensitive information that is associated with the external domain. Other a=
ttacks may be possible, such as executing script code in other browser se=
curity zones.
UPDATE: Reports indicate that Safari browser may also be vulnerable, but =
this has not been confirmed.
UPDATE (June 6, 2007): The WebKit framework used by Safari is reported vu=
lnerable. Builds 522 and later, which are associated with the nightly Web=
Kit build, are vulnerable; other versions may also be affected.
12. DVD X Player PLF File Buffer Overflow Vulnerability
BugTraq ID: 24278
Remote: Yes
Date Published: 2007-06-02
Relevant URL: http://www.securityfocus.com/bid/24278
Summary:
DVD X Player is prone to a buffer-overflow vulnerability because the appl=
ication fails to bounds-check user-supplied data before copying it into a=
n insufficiently sized buffer.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected user. Failed exploit a=
ttempts likely result in application crashes.
This issue affects DVD X Player 4.1; other versions may also be affected.
13. Microsoft Active Directory Logon Hours Username Enumeration Weakness
BugTraq ID: 24248
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24248
Summary:
Microsoft Active Directory is prone to a username-enumeration weakness be=
cause of a design error in the application when verifying user-supplied i=
nput.
Attackers may exploit this weakness to discern valid usernames. This may =
aid them in brute-force password cracking or other attacks.
Microsoft Active Directory on Microsoft Windows Server 2003 Standard Edit=
ion is vulnerable; other versions may also be affected.
14. Acoustica MP3 CD Burner PlayList Files Buffer Overflow Vulnerability
BugTraq ID: 24247
Remote: Yes
Date Published: 2007-05-31
Relevant URL: http://www.securityfocus.com/bid/24247
Summary:
Acoustica MP3 CD Burner is prone to a a buffer-overflow vulnerability bec=
ause the application fails to bounds-check user-supplied data before copy=
ing it into an insufficiently sized buffer.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the affected user. Failed exploit a=
ttempts likely result in application crashes.
15. Avira Antivir Tar Archive Handling Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 24239
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24239
Summary:
Avira Antivir is prone to a denial-of-service vulnerability because the a=
pplication fails to handle certain TAR archives.
Remote attackers may exploit this issue by enticing victims into opening=
maliciously crafted TAR archives.
A successful attack may allow attackers to cause denial-of-service condit=
ions.
16. F-Secure Multiple Products Real-time Scanning Component Local Privile=
ge Escalation Vulnerability
BugTraq ID: 24237
Remote: No
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24237
Summary:
Multiple F-Secure workstation and file-server products are prone to a loc=
al privilege-escalation vulnerability.
=20
Exploiting this vulnerability allows local attackers to gain superuser or=
SYSTEM-level privileges, leading to a complete compromise of the affecte=
d computer.
17. F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerability
BugTraq ID: 24235
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24235
Summary:
Multiple F-Secure Anti-Virus applications are prone to a buffer-overflow =
vulnerability when they process certain LHA archive files. This issue occ=
urs because the applications fail to properly check boundaries on user-su=
pplied data before copying it to an insufficiently sized memory buffer.
Successful exploits can allow attackers to execute arbitrary code with th=
e privileges of the vulnerable application. Failed exploit attempts will =
likely result in denial-of-service conditions.
Reports indicate that this vulnerability also occurs when processing malf=
ormed LZH archives, ARJ files, and FSG packed files.
18. EDraw Office Viewer Component ActiveX Control Arbitrary File Delete V=
ulnerability
BugTraq ID: 24230
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24230
Summary:
The EDraw Office Viewer Component ActiveX Control is prone to an arbitrar=
y-file-delete vulnerability.=20
An attacker can exploit this issue to delete arbitrary files on the affec=
ted computer. Successful attacks can result in denial-of-service conditio=
ns.
19. EDraw Office Viewer Component EDrawOfficeViewer.OCX ActiveX Control B=
uffer Overflow Vulnerability
BugTraq ID: 24229
Remote: Yes
Date Published: 2007-05-30
Relevant URL: http://www.securityfocus.com/bid/24229
Summary:
EDraw Office Viewer Component ActiveX control is prone to a buffer-overfl=
ow vulnerability because it fails to bounds-check user-supplied data befo=
re copying it into an insufficiently sized buffer.
An attacker can exploit this issue to cause a denial-of-service condition=
. Arbitrary code execution may be possible, but has not been confirmed.=20
This issue affects EDraw Office Viewer Component 4.0.5.20; other versions=
may also be affected.
20. Zenturi ProgramChecker SASATL.DLL ActiveX Control Multiple Buffer Ove=
rflow Vulnerabilities
BugTraq ID: 24217
Remote: Yes
Date Published: 2007-05-29
Relevant URL: http://www.securityfocus.com/bid/24217
Summary:
Several Zenturi ProgramChecker ActiveX controls are prone to multiple buf=
fer-overflow vulnerabilities because they fail to bounds-check user-suppl=
ied data before copying it into an insufficiently sized buffer.
Successfully exploiting these issues allow remote attackers to execute ar=
bitrary code in the context of the application using the ActiveX control =
(typically Internet Explorer). Failed exploit attempts likely result in d=
enial-of-service conditions.
21. Microsoft DirectX Media DXTMSFT.DLL ActiveX Control Denial of Service=
Vulnerability
BugTraq ID: 24188
Remote: Yes
Date Published: 2007-05-28
Relevant URL: http://www.securityfocus.com/bid/24188
Summary:
Microsoft DirectX Media ActiveX control is prone to a denial-of-service v=
ulnerability because it fails to perform adequate checks on user-supplied=
data.
Successfully exploiting this issue allows remote attackers to crash appl=
ications using the affected ActiveX control (typically Internet Explorer)=
. Given the nature of this issue, remote code execution may be possible, =
but this has not been confirmed.
22. Avira Antivir Antivirus Multiple Remote Vulnerabilities
BugTraq ID: 24187
Remote: Yes
Date Published: 2007-05-28
Relevant URL: http://www.securityfocus.com/bid/24187
Summary:
Avira Antivir Antivirus is prone to multiple remote vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with elevated privileges, facilitating the complete=
compromise of affected computers. Attackers may also trigger denial-of-s=
ervice conditions by crashing the application or causing infinite loops.
These issues affect:
Avira Antivir AVPack versions prior to 7.03.00.09
Engine versions prior to 7.04.00.24
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #344
http://www.securityfocus.com/archive/88/470135
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Norwich University
Norwich University's Master of Science in Information Assurance Program c=
ompliments the skills of information security professionals while prepari=
ng them to take on management roles in an organization-wide information s=
ecurity program, such as Chief Security Officers, Security Administrators=
and Chief Information Security Officers. This 18 month program is conven=
iently delivered online and is accredited by The National Security Agency=
and Department of Homeland Security as a "Center for Academic Excellence=
in Information Assurance Education"
For more information, visit http://www.msia.norwich.edu/msec