SecurityFocus Microsoft Newsletter #372
[email protected] 11 Dec 2007 19:54:46 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #372
----------------------------------------
This issue is Sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000D8=
v9
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Copyrights and Wrongs
2.The Man in the Machine
II. MICROSOFT VULNERABILITY SUMMARY
1. Easy File Sharing Web Server Directory Traversal and Multiple I=
nformation Disclosure Vulnerabilities
2. Microsoft December 2007 Advance Notification Multiple Vulnerabi=
lities
3. Drupal Shoutbox Module Multiple HTML Injection Vulnerabilities
4. Drupal TAXONOMY_SELECT_NODES() SQL Injection Vulnerability
5. Novell BorderManager Multiple Vulnerabilities
6. HFS HTTP File Server Arbitrary File Upload Vulnerability
7. Cisco Security Agent for Microsoft Windows SMB Remote Buffer Ov=
erflow Vulnerability
8. avast! Home/Professional TAR File Handling Remote Heap Overflow=
Vulnerability
9. Microsoft Optical Desktop Wireless Keyboard Weak Encryption Inf=
ormation Disclosure Vulnerability
10. Microsoft Web Proxy Auto-Discovery Proxy Spoofing Vulnerabilit=
y
11. Apple QuickTime Unspecified Remote Vulnerability
12. Microsoft Internet Explorer DHTML Object Memory Corruption Vul=
nerability
III. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #371
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Copyrights and Wrongs
By Mark Rasch
On October 1, 2007, Jammie Thomas -- a single mother living in Brainerd, =
Minnesota -- was sued in civil court for copyright infringement by the Re=
cording Industry Association of America. Three days later, the jury retur=
ned the verdict; Ms. Thomas was liable for willfully infringing the copyr=
ights on 24 songs. The fine: $222,000.=20
http://www.securityfocus.com/columnists/460
2.The Man in the Machine
By Federico Biancuzzi
In April 2007, when two security researchers demonstrated a flaw in the n=
ext-generation IPv6 routing scheme that would allow attackers to signific=
antly amplify any denial-of-service attack by a factor of at least 80, ne=
tworking expert Jun-ichiro "Itojun" Hagino worked to get Internet enginee=
rs to take the threat seriously.=20
http://www.securityfocus.com/columnists/459
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Easy File Sharing Web Server Directory Traversal and Multiple Informat=
ion Disclosure Vulnerabilities
BugTraq ID: 26771
Remote: Yes
Date Published: 2007-12-07
Relevant URL: http://www.securityfocus.com/bid/26771
Summary:
Easy File Sharing Web Server is prone to a directory-traversal and multip=
le information-disclosure vulnerabilities.
Successfully exploiting these issues allows remote attackers to upload fi=
les to arbitrary locations and to access potentially sensitive informatio=
n, which may aid in further attacks.
Easy File Sharing Web Server 4.5 is vulnerable to these issues; other ver=
sions may also be affected.
2. Microsoft December 2007 Advance Notification Multiple Vulnerabilities
BugTraq ID: 26739
Remote: Yes
Date Published: 2007-12-06
Relevant URL: http://www.securityfocus.com/bid/26739
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing seven security bulletins on December 11, 2007. The highest severity =
rating for these issues is 'Critical'.
The bulletins are as follows:
Three 'Critical' bulletins affecting Microsoft Windows, DirectX, DirectSh=
ow, Windows Media Format Runtime, and Internet Explorer
Four 'Important' bulletins affecting Microsoft Windows
These issues will be assigned individual records when the bulletins are r=
eleased.
3. Drupal Shoutbox Module Multiple HTML Injection Vulnerabilities
BugTraq ID: 26736
Remote: Yes
Date Published: 2007-12-05
Relevant URL: http://www.securityfocus.com/bid/26736
Summary:
Drupal Shoutbox module is prone to multiple HTML-injection vulnerabilitie=
s because the application fails to sufficiently sanitize user-supplied in=
put data before using it in dynamically generated content.
Attacker-supplied HTML and script code could execute in the context of th=
e affected website, potentially allowing the attacker to steal cookie-bas=
ed authentication credentials or to control how the site is rendered to t=
he user; other attacks are also possible.
Versions prior to Shoutbox 5.x-1.1 are affected by these issues.
4. Drupal TAXONOMY_SELECT_NODES() SQL Injection Vulnerability
BugTraq ID: 26735
Remote: Yes
Date Published: 2007-12-05
Relevant URL: http://www.securityfocus.com/bid/26735
Summary:
Drupal is prone to an SQL-injection vulnerability because it fails to suf=
ficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
Versions prior to Drupal 4.7.9 and 5.4 are vulnerable.
5. Novell BorderManager Multiple Vulnerabilities
BugTraq ID: 26733
Remote: Yes
Date Published: 2007-12-06
Relevant URL: http://www.securityfocus.com/bid/26733
Summary:
Novell BorderManager is prone to multiple vulnerabilities.
These issues may allow attackers to execute arbitrary code and bypass cer=
tain security controls.
Versions prior to Novell BorderManager 3.8 SP5 are affected by these iss=
ues.
6. HFS HTTP File Server Arbitrary File Upload Vulnerability
BugTraq ID: 26732
Remote: Yes
Date Published: 2007-12-05
Relevant URL: http://www.securityfocus.com/bid/26732
Summary:
HFS HTTP File Server is prone to a vulnerability that lets attackers uplo=
ad files and place them in arbitrary locations on the server. The issue o=
ccurs because the software fails to adequately sanitize user-supplied inp=
ut.=20
A successful exploit may allow the attacker to upload malicious files and=
potentially execute them; this may lead to various attacks.
This issue affects versions prior to HTTP File Server 2.2b.
7. Cisco Security Agent for Microsoft Windows SMB Remote Buffer Overflow =
Vulnerability
BugTraq ID: 26723
Remote: Yes
Date Published: 2007-12-05
Relevant URL: http://www.securityfocus.com/bid/26723
Summary:
Cisco Security Agent for Microsoft Windows is prone to a buffer-overflow =
vulnerability because it fails to properly bounds-check user-supplied dat=
a.
Remote attackers can exploit this issue to execute arbitrary machine code=
with SYSTEM-level privileges. Successful exploits will completely compro=
mise affected computers. Failed attacks will likely cause denial-of-servi=
ce conditions.
This issue affects all standalone and managed versions of Cisco Security =
Agent for Windows.
8. avast! Home/Professional TAR File Handling Remote Heap Overflow Vulner=
ability
BugTraq ID: 26702
Remote: Yes
Date Published: 2007-12-04
Relevant URL: http://www.securityfocus.com/bid/26702
Summary:
avast! is prone to a remote heap-overflow vulnerability.
This issue occurs when the application handles a malicious TAR file.
Versions prior to avast! Home and Professional 4.7.1098 are affected.
9. Microsoft Optical Desktop Wireless Keyboard Weak Encryption Informatio=
n Disclosure Vulnerability
BugTraq ID: 26693
Remote: Yes
Date Published: 2007-12-04
Relevant URL: http://www.securityfocus.com/bid/26693
Summary:
Microsoft Optical Desktop is prone to an information-disclosure vulnerabi=
lity.=20
Successfully exploiting this issue will allow an attacker to obtain sensi=
tive information that may lead to other attacks.=20
This issue affects Microsoft Optical Desktop 1000 and 2000; other version=
s may also be affected.
10. Microsoft Web Proxy Auto-Discovery Proxy Spoofing Vulnerability
BugTraq ID: 26686
Remote: Yes
Date Published: 2007-12-03
Relevant URL: http://www.securityfocus.com/bid/26686
Summary:
Microsoft Web Proxy Auto-Discovery is prone to a vulnerability that may a=
llow attackers to obtain sensitive information that may lead to further a=
ttacks.
11. Apple QuickTime Unspecified Remote Vulnerability
BugTraq ID: 26682
Remote: Yes
Date Published: 2007-12-03
Relevant URL: http://www.securityfocus.com/bid/26682
Summary:
Apple QuickTime is prone to an unspecified remote vulnerability.=20
Very few technical details are currently available. We will update this B=
ID as more information emerges.
This issue affects Apple QuickTime 7.2 for Microsoft Windows XP; other ve=
rsions may also be affected.
12. Microsoft Internet Explorer DHTML Object Memory Corruption Vulnerabil=
ity
BugTraq ID: 26427
Remote: Yes
Date Published: 2007-12-11
Relevant URL: http://www.securityfocus.com/bid/26427
Summary:
Microsoft Internet Explorer is prone to a remote memory-corruption vulner=
ability because it fails to adequately handle user-supplied input to cert=
ain DHTML object methods.
Attackers can exploit this issue to execute arbitrary code in the context=
of a user running the application. Successful attacks would compromise t=
he application and possibly the underlying computer. Failed attacks will =
cause denial-of-service conditions.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #371
http://www.securityfocus.com/archive/88/484683
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack"- White Paper=
=20
Cross-site scripting vulnerabilities in web apps allow hackers to comprom=
ise confidential information, steal cookies and create requests that can =
be mistaken for those of a valid user!! Download this *FREE* white paper =
from SPI Dynamics for a complete guide to protection!=20
https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=3D70160000000D8=
v9