SecurityFocus Microsoft Newsletter #351
[email protected] 18 Jul 2007 23:03:05 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #351
----------------------------------------
This Issue is Sponsored by: Black Hat
Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier =
technical event for ICT security experts. Featuring 30 hands-on training =
courses and 90 Briefings presentations with lots of new content and new t=
ools. Network with 4,000 delegates from 70 nations. Visit product displ=
ays by 30 top sponsors in a relaxed setting. =20
http://www.blackhat.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Security conferences versus practical knowledge
2. Achtung! New German Laws on Cybercrime
II. MICROSOFT VULNERABILITY SUMMARY
1. Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple In=
secure Methods Vulnerabilities
2. QuickerSite Default.ASP Cross-Site Scripting Vulnerability
3. Marshal MailMarshal SMTP Spam Quarantine Interface User Passwor=
d Change Vulnerability
4. Trend Micro OfficeScan Management Console Authentication Bypass=
Vulnerability
5. InterActual Player IAMCE and IAKey Remote Buffer Overflow Vulne=
rabilities
6. Microsoft Internet Explorer OnBeforeUnload Javascript Browser E=
ntrapment Vulnerability
7. Zenturi ProgramChecker SASATL.DLL ActiveX Control DebugMsgLog M=
ethod Buffer Overflow Vulnerability
8. EldoS SecureBlackbox PGPBBox.dll ActiveX Control Arbitrary File=
Overwrite Vulnerability
9. Apple QuickTime Information Disclosure and Multiple Code Execut=
ion Vulnerabilities
10. QuarkXPress Word Document Text-Import Font Handling Stack Buff=
er Overflow Vulnerability
11. AVG Anti-Virus Local Privilege Escalation Vulnerability
12. Multiple Vendors RAR Handling Remote Null Pointer Dereference =
Vulnerability
13. Adobe Flash Player SWF File Handling Remote Code Execution Vul=
nerability
14. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
15. Sun Java System Server XSLT Processing Remote Java Method Exec=
ution Vulnerability
16. Microsoft Excel Unspecified Security Vulnerability
17. Microsoft Internet Explorer Multiple Browser URI Handler Comma=
nd Injection Vulnerability
18. Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control Denial =
of Service Vulnerability
19. Media Player Classic .FLV Remote Denial Of Service Vulnerabili=
ty
20. Eltima Software Virtual Serial Port VSPort.DLL ActiveX Control=
Denial of Service Vulnerabilities
21. Symantec Norton Ghost FileBackup.DLL Multiple Denial of Servic=
e Vulnerabilities
22. Symantec Norton Ghost RemoteCommand.DLL Buffer Overflow Vulne=
rability
23. Microsoft Windows Vista Kernel Unspecified Remote Denial Of Se=
rvice Vulnerability
24. Microsoft .NET Framework JIT Compiler Remote Buffer Overflow V=
ulnerability
25. Symantec AntiVirus Corporate Edition Local Privilege Escalatio=
n Vulnerability
26. Microsoft Windows Active Directory LDAP Request Validation Rem=
ote Code Execution Vulnerability
27. Microsoft Windows Active Directory LDAP Request Validation Rem=
ote Denial Of Service Vulnerability
28. Microsoft Windows Vista Teredo Interface Firewall Bypass Vulne=
rability
29. Microsoft .NET Framework PE Loader Remote Buffer Overflow Vuln=
erability
30. Symantec AntiVirus Malformed CAB and RAR Compression Remote Vu=
lnerabilities
31. Symantec Veritas Backup Exec for Windows Server RPC Heap Buffe=
r Overflow Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. Sync Domain Account password and Local Account password
2. Restrict access
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Security conferences versus practical knowledge
By Don Parker
While the training industry as a whole has evolved rather well to suit th=
e needs of their clients, the computer conference - specifically the comp=
uter security conference - has declined in relevance to the everyday sys-=
admin and network security practitioners.
http://www.securityfocus.com/columnists/449
2. Achtung! New German Laws on Cybercrime
By Federico Biancuzzi
Germany is passing some new laws regarding cybercrime that might affect s=
ecurity professionals. Federico Biancuzzi interviewed Marco Gercke, one o=
f the experts that was invited to the parliamentary hearing, to learn mor=
e about this delicate subject. They discussed what is covered by the new =
laws, which areas remain in the dark, and how they might affect vulnerabi=
lity disclosure and the use of common tools, such as nmap.
http://www.securityfocus.com/columnists/448
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure =
Methods Vulnerabilities
BugTraq ID: 24959
Remote: Yes
Date Published: 2007-07-18
Relevant URL: http://www.securityfocus.com/bid/24959
Summary:
Data Dynamics ActiveBar ActiveX control is prone to multiple vulnerabilit=
ies caused by insecure methods. The problem stems from a design error in =
the affected application.=20
An attacker can exploit this issue to overwrite arbitrary files on the vi=
ctim's computer in the context of the vulnerable application using the Ac=
tiveX control (typically Internet Explorer). Failed exploit attempts will=
likely result in a denial-of-service condition.
=20
These issues affect version 3.1; other versions may also be affected.
2. QuickerSite Default.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 24948
Remote: Yes
Date Published: 2007-07-18
Relevant URL: http://www.securityfocus.com/bid/24948
Summary:
QuickerSite is prone to a cross-site scripting vulnerability because it f=
ails to properly sanitize user-supplied input.
Exploiting this vulnerability may allow an attacker to perform cross-site=
scripting attacks on unsuspecting users in the context of the affected w=
ebsite. As a result, the attacker may be able to steal cookie-based authe=
ntication credentials and to launch other attacks.
3. Marshal MailMarshal SMTP Spam Quarantine Interface User Password Chang=
e Vulnerability
BugTraq ID: 24936
Remote: Yes
Date Published: 2007-07-17
Relevant URL: http://www.securityfocus.com/bid/24936
Summary:
Marshal MailMarshal SMTP is prone to a vulnerability that may permit atta=
ckers to change arbitrary passwords.
Exploiting this issue may allow an attacker to change an arbitrary user's=
password, bypass the authentication mechanism, and gain unauthorized acc=
ess to the affected application. This may lead to other attacks.
Versions prior to MailMarshal SMTP6.2.1 are vulnerable.
4. Trend Micro OfficeScan Management Console Authentication Bypass Vulner=
ability
BugTraq ID: 24935
Remote: Yes
Date Published: 2007-07-17
Relevant URL: http://www.securityfocus.com/bid/24935
Summary:
Trend Micro OfficeScan is prone to an authentication-bypass vulnerability=
because it fails to adequately handle user-supplied input.
Attackers can exploit this issue to gain unauthorized access to the appli=
cation's web-based management console. Successful attacks will compromise=
the application.
OfficeScan 7.3 is vulnerable; other versions may also be affected.
5. InterActual Player IAMCE and IAKey Remote Buffer Overflow Vulnerabilit=
ies
BugTraq ID: 24919
Remote: Yes
Date Published: 2007-07-16
Relevant URL: http://www.securityfocus.com/bid/24919
Summary:
InterActual Player contains multiple ActiveX controls that are prone to b=
uffer-overflow vulnerabilities because it fails to properly bounds-check =
user-supplied input before copying it to insufficiently sized memory buff=
ers.
An attacker could exploit these issues by creating a malicious web page t=
hat would initialize the affected ActiveX controllers and execute arbitra=
ry code within the context of the user.
Exploiting this issue could allow an attacker to execute arbitrary code.
These issues affect InterActual Player 2.60.12.0717; other versions may b=
e vulnerable as well.
6. Microsoft Internet Explorer OnBeforeUnload Javascript Browser Entrapme=
nt Vulnerability
BugTraq ID: 24911
Remote: Yes
Date Published: 2007-07-14
Relevant URL: http://www.securityfocus.com/bid/24911
Summary:
Microsoft Internet Explorer is prone to a vulnerability that allows attac=
kers to trap users at a particular webpage and spoof page transitions.=20
Attackers may exploit this via a malicious page to spoof the contents and=
origin of a page that the victim may trust. This vulnerability may be us=
eful in phishing or other attacks that rely on content spoofing.
Internet Explorer 7 is vulnerable to this issue; other versions may also =
be affected.
7. Zenturi ProgramChecker SASATL.DLL ActiveX Control DebugMsgLog Method B=
uffer Overflow Vulnerability
BugTraq ID: 24883
Remote: Yes
Date Published: 2007-07-12
Relevant URL: http://www.securityfocus.com/bid/24883
Summary:
The Zenturi ProgramChecker 'sasatl.dll' ActiveX control is prone to a buf=
fer-overflow vulnerability because it fails to bounds-check user-supplied=
data before copying it into an insufficiently sized buffer.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
8. EldoS SecureBlackbox PGPBBox.dll ActiveX Control Arbitrary File Overwr=
ite Vulnerability
BugTraq ID: 24882
Remote: Yes
Date Published: 2007-07-12
Relevant URL: http://www.securityfocus.com/bid/24882
Summary:
SecureBlackbox ActiveX control is prone to a vulnerability that could per=
mit an attacker to overwrite arbitrary files.
The attacker can exploit this issue to overwrite arbitrary files on the v=
ictim's computer in the context of the vulnerable application using the A=
ctiveX control (typically Internet Explorer). This may cause denial-of-se=
rvice conditions and may also allow the attacker to execute arbitrary cod=
e on the victim's computer, which may facilitate a remote compromise.
9. Apple QuickTime Information Disclosure and Multiple Code Execution Vul=
nerabilities
BugTraq ID: 24873
Remote: Yes
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24873
Summary:
Apple QuickTime is prone to an information-disclosure and multiple remote=
code-execution vulnerabilities.
Remote attackers may exploit these issues by enticing victims into openin=
g maliciously crafted files or visiting maliciously crafted websites.
Successful exploits may allow attackers to execute arbitrary code in the =
context of a user running the vulnerable application or to obtain sensiti=
ve information. Failed exploit attempts of remote code-execution issues m=
ay result in denial-of-service conditions. Successful exploits of the inf=
ormation-disclosure issue may lead to further attacks.
10. QuarkXPress Word Document Text-Import Font Handling Stack Buffer Over=
flow Vulnerability
BugTraq ID: 24872
Remote: Yes
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24872
Summary:
QuarkXPress is prone to a remote stack-based buffer-overflow vulnerabilit=
y because the application fails to bounds-check user-supplied data before=
copying it into an insufficiently sized buffer.
Remote attackers may exploit this issue by enticing victims into opening =
maliciously crafted Word (.doc) files.
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service.
This issue affects QuarkXpress 7.2 for Microsoft Windows. Other versions =
may also be affected.
11. AVG Anti-Virus Local Privilege Escalation Vulnerability
BugTraq ID: 24870
Remote: No
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24870
Summary:
AVG Anti-Virus is prone to a local privilege-escalation vulnerability bec=
ause the application fails to properly limit unprivileged users from func=
tionality that allows them to write arbitrary data to arbitrary kernel me=
mory.
Successfully exploiting this issue allows local attackers to gain SYSTEM-=
level privileges, facilitating the complete compromise of affected comput=
ers.
AVG Anti-Virus Free Edition 7.5.446 and AVG Anti-Virus 7.5.438 are vulner=
able; other versions may also be affected.
12. Multiple Vendors RAR Handling Remote Null Pointer Dereference Vulnera=
bility
BugTraq ID: 24866
Remote: Yes
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24866
Summary:
Multiple applications using RAR are prone to a NULL-pointer dereference v=
ulnerability.
A successful attack will result in denial-of-service conditions. Attacker=
s may also be able to exploit this issue to execute arbitrary code, but t=
his has not been confirmed.
This issue affects the following:
ClamAV prior to 0.91
'UnRAR' 3.70; other versions may also be vulnerable.
Other applications using the vulnerabile 'UnRAR' utility are affected by =
this issue. We will update this BID as more information emerges.
13. Adobe Flash Player SWF File Handling Remote Code Execution Vulnerabil=
ity
BugTraq ID: 24856
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24856
Summary:
Adobe Flash Player is prone to a remote code-execution vulnerability beca=
use it fails to properly sanitize user-supplied input.=20
An attacker can exploit this issue by tricking an unsuspecting victim int=
o opening a malicious file.
A successful exploit will result in the execution of arbitrary attacker-s=
upplied code in the context of the victim running the vulnerable applicat=
ion.
Adobe Flash Player 9.0.45.0 and earlier, 8.0.34.0 and earlier, and 7.0.69=
.0 and earlier are affected.
14. CenterICQ Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 24854
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24854
Summary:
Centericq is prone to multiple remote buffer-overflow vulnerabilities bec=
ause the application fails to properly bounds-check user-supplied input b=
efore copying it to an insufficiently sized memory buffer
An attacker can exploit these issues to execute arbitrary code within the=
context of the affected application. Failed exploit attempts will result=
in a denial of service.
15. Sun Java System Server XSLT Processing Remote Java Method Execution V=
ulnerability
BugTraq ID: 24850
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24850
Summary:
Sun Java System Web Servers and Application Servers are prone to a vulner=
ability that lets attackers execute arbitrary Java methods. This issue oc=
curs because the application fails to securely process XSLT stylesheets.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary Java methods, aiding them in further attacks.
Sun Java System Web Server 7.0 for the following operating systems is aff=
ected:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
- HP-UX
Sun Java System Application Server Platform and Enterprise Editions 8.2 a=
nd Platform Edition 9.0 for the following operating systems are also affe=
cted:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
16. Microsoft Excel Unspecified Security Vulnerability
BugTraq ID: 24843
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24843
Summary:
Microsoft Excel is prone to an unspecified security vulnerability.
Very little information is currently available regarding this issue. We w=
ill update this BID as more information emerges.
17. Microsoft Internet Explorer Multiple Browser URI Handler Command Inje=
ction Vulnerability
BugTraq ID: 24837
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24837
Summary:
Microsoft Internet Explorer is prone to a vulnerability that lets attacke=
rs inject commands through the 'firefoxurl' and 'navigatorurl' protocol h=
andlers.
Exploiting these issues allows remote attackers to pass and execute arbit=
rary commands and arguments through the 'firefox.exe' and 'navigator.exe'=
processes by employing the 'firefoxurl' and 'navigatorurl' handlers.
An attacker can also employ these issues to carry out cross-browser scrip=
ting attacks by using the '-chrome' argument. This can allow the attacker=
to run JavaScript code with the privileges of trusted Chrome context and=
gain full access to Firefox and Netscape Navigator's resources.
Exploiting these issues would permit remote attackers to influence comman=
d options that can be called through the 'firefoxurl' and 'navigatorurl' =
handlers and therefore execute commands and script code with the privileg=
es of a user running the applications. Successful attacks may result in a=
variety of consequences, including remote unauthorized access.
18. Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control Denial of Serv=
ice Vulnerability
BugTraq ID: 24834
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24834
Summary:
Innovasys DockStudioXP ActiveX control is prone to a denial-of-service vu=
lnerability.
=20
An attacker may exploit this issue by enticing victims into opening a mal=
icious webpage or HTML email that invokes the affected control.
The attacker can exploit this issue to cause denial-of-service conditions=
in Internet Explorer or other applications that use the vulnerable Activ=
eX control.
19. Media Player Classic .FLV Remote Denial Of Service Vulnerability
BugTraq ID: 24830
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24830
Summary:
Media Player Classic is prone to a remote denial-of-service vulnerability=
.
Attackers can exploit this issue to crash the application. Reports indica=
te that remote code execution may also be possible, but this has not been=
confirmed.
Media Player Classic 6.4.9.0 is vulnerable; other versions may also be af=
fected.
20. Eltima Software Virtual Serial Port VSPort.DLL ActiveX Control Denial=
of Service Vulnerabilities
BugTraq ID: 24827
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24827
Summary:
Eltima Software Virtual Serial Port ActiveX control is prone to multiple =
denial-of-service vulnerabilities.
Exploiting these issues allows remote attackers to crash applications tha=
t employ the vulnerable control (typically Microsoft Internet Explorer).=20
Virtual Serial Port 5.0 is vulnerable; other versions may also be affecte=
d.
21. Symantec Norton Ghost FileBackup.DLL Multiple Denial of Service Vulne=
rabilities
BugTraq ID: 24826
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24826
Summary:
Norton Ghost is prone to multiple denial-of-service vulnerabilities.
Successful exploits may allow an attacker to cause denial-of-service cond=
itions.
22. Symantec Norton Ghost RemoteCommand.DLL Buffer Overflow Vulnerabilit=
y
BugTraq ID: 24825
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24825
Summary:
Symantec Norton Ghost is prone to a buffer-overflow vulnerability because=
the application fails to bounds-check user-supplied data before copying =
it into an insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.=20
This issue affects Symantec Ghost 12.0; other versions may also be affect=
ed.
23. Microsoft Windows Vista Kernel Unspecified Remote Denial Of Service V=
ulnerability
BugTraq ID: 24816
Remote: Yes
Date Published: 2007-07-09
Relevant URL: http://www.securityfocus.com/bid/24816
Summary:
Microsoft Windows Vista is prone to an unspecified remote denial-of-servi=
ce vulnerability.
Attackers may exploit this issue to crash the affected operating system, =
denying further service to legitimate users. Remote code-execution may be=
possible, but this has not been confirmed.
24. Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerab=
ility
BugTraq ID: 24811
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24811
Summary:
Microsoft .NET Framework is prone to a remote buffer-overflow vulnerabili=
ty because it fails to perform adequate boundary checks on user-supplied =
data.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of a user running the application. Successful exploits can result in t=
he complete compromise of affected computers. Failed attacks will likely =
result in denial-of-service conditions.
25. Symantec AntiVirus Corporate Edition Local Privilege Escalation Vulne=
rability
BugTraq ID: 24810
Remote: No
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24810
Summary:
Symantec AntiVirus Corporate Edition is prone to a local privilege-escala=
tion vulnerability because the application fails to properly drop privile=
ges.
A local attacker can exploit this issue to elevate privileges to the SYST=
EM level. This could facilitate a complete compromise of the affected com=
puter.
26. Microsoft Windows Active Directory LDAP Request Validation Remote Cod=
e Execution Vulnerability
BugTraq ID: 24800
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24800
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability becau=
se Microsoft Active Directory fails to handle specially crafted user-supp=
lied Lightweight Directory Access Protocol (LDAP) requests.=20
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.
27. Microsoft Windows Active Directory LDAP Request Validation Remote Den=
ial Of Service Vulnerability
BugTraq ID: 24796
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24796
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause Microsoft Active Directory fails to handle specially crafted Lightw=
eight Directory Access Protocol (LDAP) requests.=20
An attacker can exploit this issue to cause the affected application to s=
top responding, denying further service to legitimate users.
28. Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerabilit=
y
BugTraq ID: 24779
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24779
Summary:
Windows Firewall for Windows Vista is prone to a vulnerability that may p=
ermit a bypass of existing firewall rules.
An attacker may trigger this vulnerability by sending malicious network d=
ata through the Teredo network transport system to obtain sensitive infor=
mation; other attacks are also possible.
Note that Windows Vista systems configured with a 'Public' network profil=
e are not vulnerable to this issue.
29. Microsoft .NET Framework PE Loader Remote Buffer Overflow Vulnerabili=
ty
BugTraq ID: 24778
Remote: Yes
Date Published: 2007-07-10
Relevant URL: http://www.securityfocus.com/bid/24778
Summary:
Microsoft .NET Framework is prone to a remote buffer-overflow vulnerabili=
ty because it fails to perform adequate boundary checks on user-supplied =
data.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of a user running the application. Successful exploits can result in t=
he complete compromise of affected computers. Failed attacks will likely =
result in denial-of-service conditions.
30. Symantec AntiVirus Malformed CAB and RAR Compression Remote Vulnerabi=
lities
BugTraq ID: 24282
Remote: Yes
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/24282
Summary:
Symantec AntiVirus products that include the Symantec Decomposer are pron=
e to multiple remote vulnerabilities related to the handling of CAB and R=
AR archives. These issues include a denial-of-service vulnerability and a=
buffer-overflow vulnerability.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with SYSTEM-level privileges or to cause the affect=
ed application to enter an infinite loop, resulting in a denial-of-servic=
e condition.
31. Symantec Veritas Backup Exec for Windows Server RPC Heap Buffer Overf=
low Vulnerability
BugTraq ID: 23897
Remote: Yes
Date Published: 2007-07-11
Relevant URL: http://www.securityfocus.com/bid/23897
Summary:
Symantec Veritas Backup Exec for Windows Server is prone to a heap-based =
buffer-overflow vulnerability because the application fails to bounds-che=
ck user-supplied data before copying it into an insufficiently sized buff=
er.=20
An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Sync Domain Account password and Local Account password
http://www.securityfocus.com/archive/88/473988
2. Restrict access
http://www.securityfocus.com/archive/88/473787
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Black Hat
Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier =
technical event for ICT security experts. Featuring 30 hands-on training =
courses and 90 Briefings presentations with lots of new content and new t=
ools. Network with 4,000 delegates from 70 nations. Visit product displ=
ays by 30 top sponsors in a relaxed setting. =20
http://www.blackhat.com