SecurityFocus Microsoft Newsletter #357

[email protected] 29 Aug 2007 22:36:40 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #357
----------------------------------------

This Issue is Sponsored by: SPI Dynamics

XPATH Injection Attacks- Web Hackers New Trick: White Paper=20
One particular form of injection attack, XPath Injection, is rapidly gain=
ing in popularity due to the spread of AJAX applications and their inhere=
nt use of XML to store data.=20
XPath Injection can be just as dangerous as SQL Injection, and can be eve=
n easier to exploit. Learn how to identify XPath Injection vulnerabilitie=
s and which methods of recourse to take to prevent them. Download this *F=
REE* white paper from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/XP.asp?Campaign_ID=3D70160000000D1r=
X


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Virtualized rootkits - Part 2
       2. Virtualized rootkits - Part 1
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Oracle JInitiator ActiveX Control Multiple Buffer Overflow Vuln=
erabilities
       2. Entrust ESP Certificate Path Verification Vulnerability
       3. Subversion for Windows Remote Directory Traversal Vulnerability
       4. Microsoft MSN Messenger Video Conversation Buffer Overflow Vuln=
erability
       5. Motorola Timbuktu Pro for Windows Multiple Remote Buffer Overfl=
ow Vulnerabilities
       6. Motorola Timbuktu Pro Directory Traversal Vulnerability
       7. BufferZone Redlight.SYS Driver Buffer Overflow Vulnerability
       8. Media Player Classic FLI File Remote Buffer Overflow Vulnerabil=
ity
       9. Soldat Multiple Remote Denial of Service Vulnerabilities
       10. Bugzilla Multiple Remote Vulnerabilities
       11. Skulltag Huffman Packet Decompression Remote Heap Based Buffer=
 Overflow Vulnerability
       12. Unreal Commander Malformed Archives Multiple Remote Vulnerabil=
ities
       13. IBM Lotus Notes NTMulti.EXE Local Privilege Escalation Vulnera=
bility
       14. Clam AntiVirus ClamAV Multiple Remote Denial of Service Vulner=
abilities
       15. Trend Micro Anti-Spyware And PC-cillin SSAPI Engine Local Stac=
k Buffer Overflow Vulnerability
       16. Check Point Zone Labs Multiple Products Local Privilege Escala=
tion Vulnerabilities
III. MICROSOFT FOCUS LIST SUMMARY
       1. Software smart-card emulation
       2. SecurityFocus Microsoft Newsletter #356
       3. NTFS default special permissions
       4. Password complexity - improvement
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Virtualized rootkits - Part 2
By Federico Biancuzzi
There has been a lot of buzz around the topic of virtualized rootkits. Jo=
anna Rutkowska has been working on a new version of Blue-Pill, her proof =
of concept invisible rootkit, while a team made by three prominent securi=
ty experts (Thomas Ptacek, Nate Lawson, Peter Ferrie) challenged her that=
 there is not an "invisible" rootkit, and that they were going to present=
 at BlackHat conference various techniques to detect Blue-Pill. Federico =
Biancuzzi interviewed both sides to learn more. Part 2 of 2
http://www.securityfocus.com/columnists/452


2. Virtualized rootkits - Part 1
By Federico Biancuzzi
There has been a lot of buzz around the topic of virtualized rootkits. Jo=
anna Rutkowska has been working on a new version of Blue-Pill, her proof =
of concept invisible rootkit, while a team made by three prominent securi=
ty experts (Thomas Ptacek, Nate Lawson, Peter Ferrie) challenged her that=
 there is not an "invisible" rootkit, and that they were going to present=
 at BlackHat conference various techniques to detect Blue-Pill. Federico =
Biancuzzi interviewed both sides to learn more. Part 1 of 2
http://www.securityfocus.com/columnists/451


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Oracle JInitiator ActiveX Control Multiple Buffer Overflow Vulnerabili=
ties
BugTraq ID: 25473
Remote: Yes
Date Published: 2007-08-28
Relevant URL: http://www.securityfocus.com/bid/25473
Summary:
Oracle JInitiator is prone to multiple remote buffer-overflow vulnerabili=
ties because the application fails to properly bounds-check user-supplied=
 data before copying it into an insufficiently sized memory buffer.

Exploiting these issues allows remote attackers to execute arbitrary code=
 in the context of applications using the affected ActiveX control and to=
 compromise affected computers. Failed attempts will likely result in den=
ial-of-service conditions.

These issues affect Oracle JInitiator version 1.1.8.16; other versions ma=
y also be affected.

2. Entrust ESP Certificate Path Verification Vulnerability
BugTraq ID: 25471
Remote: Yes
Date Published: 2007-08-28
Relevant URL: http://www.securityfocus.com/bid/25471
Summary:
Entrust ESP is prone to a certificate path verification vulnerability. Th=
is issue is due to a failure of the application to properly validate cert=
ificate chains.

Successfully exploiting this issue may allow attackers to utilize invalid=
 security certificates, possibly aiding in further attacks.

Entrust Entelligence Security Provider 8 is vulnerable to this issue. Oth=
er versions may also be affected.

3. Subversion for Windows Remote Directory Traversal Vulnerability
BugTraq ID: 25468
Remote: Yes
Date Published: 2007-08-28
Relevant URL: http://www.securityfocus.com/bid/25468
Summary:
Subversion is prone to a remote directory-traversal vulnerability. This i=
ssue is due to a failure of the application to properly sanitize user-sup=
plied input.

Successfully exploiting this issue allows attackers to write arbitrary da=
ta to arbitrary locations on unsuspecting users' computers.

This issue affects Subversion running on the Microsoft Windows platforms,=
 and on any other platform where directory separator characters are '\' o=
r characters other than '/'.

Subversion versions prior to 1.4.5 are vulnerable to this issue.

4. Microsoft MSN Messenger Video Conversation Buffer Overflow Vulnerabili=
ty
BugTraq ID: 25461
Remote: Yes
Date Published: 2007-08-28
Relevant URL: http://www.securityfocus.com/bid/25461
Summary:
Microsoft MSN Messenger is prone to a buffer-overflow vulnerability becau=
se it fails to perform adequate boundary checks on user-supplied data.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application. Failed exploit attempts wi=
ll likely result in denial of service conditions.

Microsoft MSN Messenger version 7 is considered vulnerable; other version=
s may also be prone to this issue.

5. Motorola Timbuktu Pro for Windows Multiple Remote Buffer Overflow Vuln=
erabilities
BugTraq ID: 25454
Remote: Yes
Date Published: 2007-08-27
Relevant URL: http://www.securityfocus.com/bid/25454
Summary:
Motorola Timbuktu Pro is prone to multiple remote buffer-overflow vulnera=
bilities. These issues are due to a failure of the software to properly b=
ounds-check user-supplied input.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code with SYSTEM-level privileges. This facilitates the =
complete remote compromise of affected computers. Failed exploit attempts=
 likely result in denial-of-service conditions.

Timbuktu Pro version 8.6.3.1367 for Microsoft Windows is vulnerable to th=
ese issues. Other versions and platforms may also be affected.

6. Motorola Timbuktu Pro Directory Traversal Vulnerability
BugTraq ID: 25453
Remote: Yes
Date Published: 2007-08-27
Relevant URL: http://www.securityfocus.com/bid/25453
Summary:
Motorola Timbuktu Pro is prone to a directory-traversal vulnerability bec=
ause it fails to sufficiently sanitize user-supplied input data.

Exploiting this issue may allow an attacker to delete or create arbitrary=
 files with SYSTEM-level privileges. This could completely compromise aff=
ected computers.

Timbuktu Pro for Windows version 8.6.3.1367 is vulnerable; other versions=
 and platforms may also be affected.

7. BufferZone Redlight.SYS Driver Buffer Overflow Vulnerability
BugTraq ID: 25442
Remote: No
Date Published: 2007-08-25
Relevant URL: http://www.securityfocus.com/bid/25442
Summary:
BufferZone is prone to a buffer-overflow vulnerability because the applic=
ation fails to bounds-check user-supplied data before copying it into an =
insufficiently sized buffer.=20

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial-of-service condition.

This issue affects BufferZone version 2.5; prior versions may also be aff=
ected.

8. Media Player Classic FLI File Remote Buffer Overflow Vulnerability
BugTraq ID: 25437
Remote: Yes
Date Published: 2007-08-24
Relevant URL: http://www.securityfocus.com/bid/25437
Summary:
Media Player Classic is prone to a buffer-overflow vulnerability because =
the application fails to properly bounds-check user-supplied data.

Attackers may attempt to exploit this issue by coercing users to access m=
alicious FLI files.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of the user running the affected appli=
cation. This facilitates the remote compromise of affected computers.

Media Player Classic version 6.4.9.0 is vulnerable; other versions may al=
so be affected.

9. Soldat Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 25426
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25426
Summary:
Soldat is prone to multiple remote denial-of-service vulnerabilities. The=
se issues are due to failures of the game software when handling unexpect=
ed input.

Successfully exploiting these issues allows remote attackers to crash gam=
e servers and clients, or to block arbitrary IP addresses from connecting=
 to game servers.

Soldat version 1.4.2 and Soldat dedicated server version 2.6.2 are vulner=
able to these issues; other versions may also be affected.

10. Bugzilla Multiple Remote Vulnerabilities
BugTraq ID: 25425
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25425
Summary:
Bugzilla is prone to multiple remote vulnerabilities. These issues includ=
e an HTML-injection vulnerability, a remote-command injection vulnerabili=
ty and an information-disclosure vulnerability.

An attacker can exploit this issue to execute arbitrary code and commands=
 with the privileges of the webserver process, steal cookie-based authent=
ication credentials and disclose sensitive information.=20

 This issue affects Bugzilla 2.20.4, 2.22.2, 3.0, 3.1; prior versions of =
the 2.20 and 2.22 branches are also affected.

11. Skulltag Huffman Packet Decompression Remote Heap Based Buffer Overfl=
ow Vulnerability
BugTraq ID: 25423
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25423
Summary:
Skulltag is prone to a remote heap-based buffer-overflow vulnerability be=
cause it fails to perform adequate boundary-checks on user-supplied input=
.

Attackers can exploit this issue to execute arbitrary code with the privi=
leges of the user running the application. Successful exploits may compro=
mise affected computers. Failed attacks will likely cause denial-of-servi=
ce conditions.

Skulltag version 0.97d-beta4.1 is vulnerable; other versions may also be =
affected.

12. Unreal Commander Malformed Archives Multiple Remote Vulnerabilities
BugTraq ID: 25419
Remote: Yes
Date Published: 2007-08-23
Relevant URL: http://www.securityfocus.com/bid/25419
Summary:
Unreal Commander is prone to multiple remote vulnerabilities when handlin=
g malformed ZIP and RAR archives. These vulnerabilities include a directo=
ry-traversal vulnerability, an information-disclosure vulnerability and a=
 file-name spoofing vulnerability.=20

An attacker can exploit these issues to compromise the affected computer,=
 overwrite arbitrary files and disclose sensitive information. These issu=
es may lead to other attacks.=20

Unreal Commander version 0.92 (build 565) and version 0.92 (build 573) ar=
e vulnerable; prior versions may also be affected.

13. IBM Lotus Notes NTMulti.EXE Local Privilege Escalation Vulnerability
BugTraq ID: 25401
Remote: No
Date Published: 2007-08-22
Relevant URL: http://www.securityfocus.com/bid/25401
Summary:
IBM Lotus Notes is prone to a local privilege-escalation vulnerability be=
cause it fails to assigned proper file permissions during installation.

Attackers can exploit this issue to run arbitrary applications with SYSTE=
M-level privileges. Successful attacks will completely compromise affecte=
d computers.

NOTE: This issue may be related to the one covered under BID 20612. This =
has not been confirmed. This BID will be updated as further information b=
ecomes available.

14. Clam AntiVirus ClamAV Multiple Remote Denial of Service Vulnerabiliti=
es
BugTraq ID: 25398
Remote: Yes
Date Published: 2007-08-21
Relevant URL: http://www.securityfocus.com/bid/25398
Summary:
ClamAV is prone to multiple denial-of-service vulnerabilities.

A successful attack may allow an attacker to crash the application and de=
ny service to users.

ClamAV versions prior to 0.91.2 are vulnerable to these issues.

15. Trend Micro Anti-Spyware And PC-cillin SSAPI Engine Local Stack Buffe=
r Overflow Vulnerability
BugTraq ID: 25388
Remote: No
Date Published: 2007-08-21
Relevant URL: http://www.securityfocus.com/bid/25388
Summary:
Trend Micro Anti-Spyware and PC-cillin Internet Security are prone to a l=
ocal stack buffer-overflow vulnerability because it fails to properly bou=
nds-check user-supplied data before copying it into an insufficiently siz=
ed memory buffer.

This issue affects a library in Trend Micro's SSAPI Engine.

Successful exploits may allow an attacker to execute arbitrary code with =
SYSTEM-level privileges. This may facilitate a complete compromise of vul=
nerable servers. Failed exploit attempts will likely result in denial-of-=
service conditions.

Trend Micro Anti-Spyware for Consumer version 3.5 and PC-cillin Internet =
Security 2007 are vulnerable.

16. Check Point Zone Labs Multiple Products Local Privilege Escalation Vu=
lnerabilities
BugTraq ID: 25365
Remote: No
Date Published: 2007-08-20
Relevant URL: http://www.securityfocus.com/bid/25365
Summary:
Multiple Check Point ZoneLabs products are prone to multiple local privil=
ege-escalation vulnerabilities.

Successfully exploiting these issues allows local attackers to execute ar=
bitrary code with elevated privileges, facilitating the complete compromi=
se of affected computers.

ZoneAlarm versions prior to 7.0.362 are vulnerable, as well as ZoneLabs p=
roducts that include 'vsdatant.sys' version 6.5.737.0.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Software smart-card emulation
http://www.securityfocus.com/archive/88/478049

2. SecurityFocus Microsoft Newsletter #356
http://www.securityfocus.com/archive/88/477495

3. NTFS default special permissions
http://www.securityfocus.com/archive/88/477517

4. Password complexity - improvement
http://www.securityfocus.com/archive/88/476610

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics

XPATH Injection Attacks- Web Hackers New Trick: White Paper=20
One particular form of injection attack, XPath Injection, is rapidly gain=
ing in popularity due to the spread of AJAX applications and their inhere=
nt use of XML to store data.=20
XPath Injection can be just as dangerous as SQL Injection, and can be eve=
n easier to exploit. Learn how to identify XPath Injection vulnerabilitie=
s and which methods of recourse to take to prevent them. Download this *F=
REE* white paper from SPI Dynamics for a complete guide to protection!=20

https://download.spidynamics.com/1/ad/XP.asp?Campaign_ID=3D70160000000D1r=
X