SecurityFocus Microsoft Newsletter #367
[email protected] 8 Nov 2007 04:46:37 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #367
----------------------------------------
This issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored.=20
This paper examines a few vulnerability detection methods - specifically =
comparing and contrasting manual penetration testing with automated scann=
ing tools.
Download Watchfire's "Web Application Security: Automated Scanning or Man=
ual Penetration Testing?" whitepaper today!=20
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D7017000000093z=
v
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.E-mail privacy to disappear?
2.Rebinding attacks unbound
II. MICROSOFT VULNERABILITY SUMMARY
1. Microsoft DebugView Kernel Module Dbgv.SYS Local Privilege Esca=
lation Vulnerability
2. Apple QuickTime PICT Image Remote Multiple Heap Buffer Overflow=
Vulnerabilities
3. Apple QuickTime PICT Image Remote Stack Buffer Overflow Vulnera=
bility
4. Apple QuickTime Panorama Sample Atoms Remote Heap Buffer Overfl=
ow Vulnerability
5. Apple QuickTime STSD Atom Remote Heap Buffer Overflow Vulnerabi=
lity
6. Apple QuickTime Image Description Atom Remote Memory Corruption=
Vulnerability
7. Apple QuickTime for Java Multiple Unspecified Remote Privilege =
Escalation Vulnerabilities
8. Apple QuickTime Color Table Atom Remote Heap Buffer Overflow Vu=
lnerability
9. Novell BorderManager Client Trust Heap Based Buffer Overflow Vu=
lnerability
10. Mono System.Math BigInteger Buffer Overflow Vulnerability
11. Symantec Altiris Deployment Solution Directory Traversal Vulne=
rability
12. Symantec Altiris Deployment Solution Aclient Local Privilege E=
scalation Vulnerability
13. Ipswitch IMail SMTP Server IMail Client Remote Buffer Overflow=
Vulnerability
14. Sony CONNECT SonicStage Player M3U Playlist Processing Buffer =
Overflow Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.E-mail privacy to disappear?
On October 8, 2007, the United States Court of Appeals for the Sixth Circ=
uit in Cincinnati granted the government's request for a full-panel heari=
ng in United States v. Warshak case centering on the right of privacy for=
stored electronic communications. At issue is whether the procedure wher=
eby the government can subpoena stored copies of your e-mail -- similar t=
o the way they could simply subpoena any physical mail sitting on your de=
sk -- is unconstitutionally broad.=20
http://www.securityfocus.com/columnists/456
2.Rebinding attacks unbound
By Federico Biancuzzi
DNS rebinding was discovered in 1996 and affected the Java Virtual Machin=
e (VM). Recently a group of researchers at Stanford found out that this v=
ulnerability is still present in browsers and that the common solution, k=
nown as DNS pinning, is not effective anymore.
http://www.securityfocus.com/columnists/455
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Microsoft DebugView Kernel Module Dbgv.SYS Local Privilege Escalation =
Vulnerability
BugTraq ID: 26359
Remote: No
Date Published: 2007-11-06
Relevant URL: http://www.securityfocus.com/bid/26359
Summary:
Microsoft DebugView is prone to a local privilege-escalation vulnerabilit=
y because it allows user-supplied data to be copied into memory addresses=
reserved for the kernel.
An attacker could exploit this issue to execute arbitrary machine code wi=
th SYSTEM-level privileges. A successful exploit could result in the comp=
lete compromise of the affected computer. Failed attempts could cause den=
ial-of-service conditions.
Microsoft DebugView 4.64 is vulnerable; other versions may also be affect=
ed.
2. Apple QuickTime PICT Image Remote Multiple Heap Buffer Overflow Vulner=
abilities
BugTraq ID: 26345
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26345
Summary:
Apple QuickTime is prone to multiple heap-based buffer-overflow vulnerabi=
lities because it fails to perform adequate boundary checks on user-suppl=
ied data.
An attacker can exploit these issues by enticing an unsuspecting user to =
open a specially crafted PICT image file.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the user running the application. Failed =
exploit attempts likely result in denial-of-service conditions.
These issues affects Apple QuickTime running on Microsoft Windows Vista, =
Microsoft Windows XP SP2, and Mac OS X.
3. Apple QuickTime PICT Image Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 26344
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26344
Summary:
Apple QuickTime is prone to a stack-based buffer-overflow issue because i=
t fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user to op=
en a specially crafted image file.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application. Failed ex=
ploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Mi=
crosoft Windows XP SP2, and Mac OS X.
4. Apple QuickTime Panorama Sample Atoms Remote Heap Buffer Overflow Vuln=
erability
BugTraq ID: 26342
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26342
Summary:
Apple QuickTime is prone to a heap-based buffer-overflow issue because it=
fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user to op=
en a specially crafted movie file.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application. Failed ex=
ploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Mi=
crosoft Windows XP SP2, and Mac OS X.
5. Apple QuickTime STSD Atom Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 26341
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26341
Summary:
Apple QuickTime is prone to a heap-based buffer-overflow issue because it=
fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user to op=
en a specially crafted movie file.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application. Failed ex=
ploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Mi=
crosoft Windows XP SP2, and Mac OS X.
6. Apple QuickTime Image Description Atom Remote Memory Corruption Vulner=
ability
BugTraq ID: 26340
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26340
Summary:
Apple QuickTime is prone to a memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user to op=
en a specially crafted movie file.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application. Failed ex=
ploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Mi=
crosoft Windows XP SP2, and Mac OS X.
7. Apple QuickTime for Java Multiple Unspecified Remote Privilege Escalat=
ion Vulnerabilities
BugTraq ID: 26339
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26339
Summary:
Apple QuickTime for Java is prone to multiple unspecified privilege-escal=
ation vulnerabilities.
Successfully exploiting these issues allows remote attackers to access po=
tentially sensitive information or to execute arbitrary code with elevate=
d privileges. These issues facilitate the remote compromise of affected c=
omputers.
These issues affect QuickTime for Java for both Apple Mac OS X and Micros=
oft Windows platforms.
8. Apple QuickTime Color Table Atom Remote Heap Buffer Overflow Vulnerabi=
lity
BugTraq ID: 26338
Remote: Yes
Date Published: 2007-11-05
Relevant URL: http://www.securityfocus.com/bid/26338
Summary:
Apple QuickTime is prone to a heap-based buffer-overflow issue because it=
fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user to op=
en a specially crafted movie file.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application. Failed ex=
ploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime running on Microsoft Windows Vista, Mi=
crosoft Windows XP SP2, and Mac OSX.
9. Novell BorderManager Client Trust Heap Based Buffer Overflow Vulnerabi=
lity
BugTraq ID: 26285
Remote: Yes
Date Published: 2007-10-31
Relevant URL: http://www.securityfocus.com/bid/26285
Summary:
Novell BorderManager is prone to a heap-based buffer-overflow vulnerabili=
ty because the application fails to bounds-check user-supplied data befor=
e copying it into an insufficiently sized buffer.=20
An attacker may exploit this issue to execute arbitrary code within the c=
ontext of the affected application or crash the application, denying serv=
ice to legitimate users.
This issue affects BorderManager 3.8; other versions may also be vulnerab=
le.
10. Mono System.Math BigInteger Buffer Overflow Vulnerability
BugTraq ID: 26279
Remote: Yes
Date Published: 2007-10-31
Relevant URL: http://www.securityfocus.com/bid/26279
Summary:
Mono is prone to a buffer-overflow vulnerability because the application =
fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue could allow attackers to execute arbit=
rary code in the context of the user running an affected application. Fai=
led exploit attempts will likely result in a denial-of-service condition.
11. Symantec Altiris Deployment Solution Directory Traversal Vulnerabilit=
y
BugTraq ID: 26266
Remote: No
Date Published: 2007-10-30
Relevant URL: http://www.securityfocus.com/bid/26266
Summary:
Symantec Altiris Deployment Solution is prone to a directory-traversal vu=
lnerability.
Attackers can exploit this issue to access potentially sensitive informat=
ion that may aid in further attacks.
12. Symantec Altiris Deployment Solution Aclient Local Privilege Escalati=
on Vulnerability
BugTraq ID: 26265
Remote: No
Date Published: 2007-10-30
Relevant URL: http://www.securityfocus.com/bid/26265
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.
Attackers can exploit this issue to execute arbitrary files with 'System'=
privileges. Successful exploits will completely compromise affected comp=
uters.
13. Ipswitch IMail SMTP Server IMail Client Remote Buffer Overflow Vulner=
ability
BugTraq ID: 26252
Remote: Yes
Date Published: 2007-10-30
Relevant URL: http://www.securityfocus.com/bid/26252
Summary:
IMail Client, which is included in Ipswitch IMail Server, is prone to a b=
uffer-overflow vulnerability because the software fails to properly bound=
s-check user-supplied input before copying it into an insufficiently size=
d memory buffer.
Attackers may exploit this issue to execute arbitrary code in the context=
of the affected application. Failed exploit attempts will likely result =
in denial-of-service conditions.
This issue affects IMail Client 9.22, which is included with IMail Server=
2006.22; other versions may also be affected.
14. Sony CONNECT SonicStage Player M3U Playlist Processing Buffer Overflo=
w Vulnerability
BugTraq ID: 26241
Remote: Yes
Date Published: 2007-10-29
Relevant URL: http://www.securityfocus.com/bid/26241
Summary:
Sony CONNECT SonicStage player is prone to a buffer-overflow vulnerabilit=
y because it fails to properly bounds-check user-supplied input before co=
pying it to an insufficiently sized memory buffer.
Remote attackers may crash the application or execute arbitrary machine c=
ode in the context of the user running the affected application.
This issue affects SonicStage 4.3; other versions may also be vulnerable.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Watchfire
As web applications become increasingly complex, tremendous amounts of se=
nsitive data - including personal, medical and financial information - ar=
e exchanged, and stored.=20
This paper examines a few vulnerability detection methods - specifically =
comparing and contrasting manual penetration testing with automated scann=
ing tools.
Download Watchfire's "Web Application Security: Automated Scanning or Man=
ual Penetration Testing?" whitepaper today!=20
https://www.watchfire.com/securearea/whitepapers.aspx?id=3D7017000000093z=
v