SecurityFocus Microsoft Newsletter #380

[email protected] 9 Feb 2008 05:34:16 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #380
----------------------------------------

This issue is Sponsored by: Black Hat Europe

Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content.  Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Skills for the Future
       2. Mother, May I?

II.  MICROSOFT VULNERABILITY SUMMARY
       1. COWON America jetAudio ASX File Processing Remote Buffer Overfl=
ow Vulnerability
       2. IBM DB2 Universal Database DAS Buffer Overflow Vulnerability
       3. IBM DB2 Universal Database Server 'db2db' Local Privilege Escal=
ation Vulnerability
       4. Check Point VPN SecureClient/SecuRemote Local Login Credentials=
 Information Disclosure Vulnerability
       5. Microsoft February 2008 Advance Notification Multiple Vulnerabi=
lities
       6. IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vu=
lnerability
       7. TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnera=
bilities
       8. WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Au=
thentication Bypass Vulnerability
       9. Ipswitch FTP Log Server Denial of Service Vulnerability
       10. Titan FTP Server DELE Command Remote Buffer Overflow Vulnerabi=
lity
       11. Print Manager Plus PQCore Remote Denial of Service Vulnerabili=
ty
       12. Xlight FTP Server LDAP Blank Password Authentication Bypass Vu=
lnerability
       13. IBM DB2 Universal Database Server 8.2 Prior To Fixpak 16 Multi=
ple Local Vulnerabilities
       14. Ipswitch WS_FTP SFTP Opendir Command Buffer Overflow Vulnerabi=
lity
       15. Titan FTP Server USER/PASS Commands Buffer Overflow Vulnerabil=
ity
       16. ELOG 'logbook' HTML Injection Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #379
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Skills for the Future
By Don Parker
A lot of the emails sent to me ask a basic question: Just how does one br=
eak into computer security or what skills should you learn to get that fi=
rst security job. Lately though, I have been receiving many more queries =
on specifically how one can leverage an existing skill set to become an i=
nformation-technology security analyst.
http://www.securityfocus.com/columnists/464

2. Mother May I?
By Mark Rasch
"Sure, you can have a cookie, but you may not."We all have had that discu=
ssion before -- either with our parents or our kids. A recent case from N=
orth Dakota reveals that the difference between those two concepts may le=
ad not only to civil liability, but could land you in jail.
http://www.securityfocus.com/columnists/463



II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. COWON America jetAudio ASX File Processing Remote Buffer Overflow Vuln=
erability
BugTraq ID: 27698
Remote: Yes
Date Published: 2008-02-08
Relevant URL: http://www.securityfocus.com/bid/27698
Summary:
jetAudio is prone to a remote buffer-overflow vulnerability because the a=
pplication fails to properly bounds-check user-supplied data before copyi=
ng it to an insufficiently sized buffer while processing ASX files.

Exploiting this issue allows attackers to execute arbitrary machine code =
in the context of users running the affected application.

jetAudio 7.0.5 is reported vulnerable; prior versions may also be affecte=
d.

2. IBM DB2 Universal Database DAS Buffer Overflow Vulnerability
BugTraq ID: 27681
Remote: Yes
Date Published: 2008-02-07
Relevant URL: http://www.securityfocus.com/bid/27681
Summary:
IBM DB2 is prone to a buffer-overflow vulnerability because the applicati=
on fails to perform adequate boundary checks on user-supplied data.

Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected service. Successfully exploiting this issue may faci=
litate in the remote compromise of affected computers. Failed exploit att=
empts will likely crash the affected application.

NOTE: This vulnerability was previously disclosed in BID 27596 (IBM DB2 U=
niversal Database Server 8.2 Prior To Fixpak 16 Multiple Local Vulnerabil=
ities). Due to more information, it has been assigned its own record.

3. IBM DB2 Universal Database Server 'db2db' Local Privilege Escalation V=
ulnerability
BugTraq ID: 27680
Remote: No
Date Published: 2008-02-07
Relevant URL: http://www.securityfocus.com/bid/27680
Summary:
IBM DB2 Universal Database Server is prone to a local privilege-escalatio=
n vulnerability because of how the application contructs library paths.

Exploiting this issue allows local attackers to gain root privileges.  No=
te that an attacker must be able to execute the set-uid root 'db2pd' bina=
ry to exploit this issue.

DB2 Universal Database Server 9.1 FixPack 2 on Linux systems is vulnerabl=
e. Other versions, including those for other UNIX platforms, are suspecte=
d to be vulnerable.

NOTE: This vulnerability was previously disclosed in BID 27596 'IBM DB2 U=
niversal Database Server 8.2 Prior To Fixpak 16 Multiple Local Vulnerabil=
ities'.  Due to more information, it has been assigned its own record.

4. Check Point VPN SecureClient/SecuRemote Local Login Credentials Inform=
ation Disclosure Vulnerability
BugTraq ID: 27675
Remote: No
Date Published: 2008-02-07
Relevant URL: http://www.securityfocus.com/bid/27675
Summary:
Check Point VPN-1 SecureClient/SecuRemote client for Microsoft Windows is=
 prone to an information-disclosure vulnerability because it fails to pro=
tect users' login credentials.

Attackers can exploit this issue to harvest VPN login credentials and gai=
n unauthorized access to  networks and resources protected by the VPN.  T=
his may lead to further attacks.

5. Microsoft February 2008 Advance Notification Multiple Vulnerabilities
BugTraq ID: 27674
Remote: Yes
Date Published: 2008-02-07
Relevant URL: http://www.securityfocus.com/bid/27674
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing twelve security bulletins on February 12, 2008. The highest severity=
 rating for these issues is 'Critical'.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

Individual records will be created for each issue when the bulletins are =
released.

6. IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerabi=
lity
BugTraq ID: 27665
Remote: Yes
Date Published: 2008-02-05
Relevant URL: http://www.securityfocus.com/bid/27665
Summary:
IBM WebSphere Edge Server Caching Proxy is prone to a cross-site scriptin=
g vulnerability that affects the caching proxy server because it fails to=
 properly sanitize user-supplied input.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

The vulnerability affects Caching Proxy 5.1, 5.1.1, 6.0, 6.0.1, 6.0.2, an=
d 6.1. Other versions may also be affected.

7. TinTin++ and WinTin++ '#chat' Command Multiple Security Vulnerabilitie=
s
BugTraq ID: 27660
Remote: Yes
Date Published: 2008-02-06
Relevant URL: http://www.securityfocus.com/bid/27660
Summary:
TinTin++ and WinTin++ are prone to multiple security vulnerabilities affe=
cting the application's '#chat' functionality.  These issues include a bu=
ffer-overflow vulnerability, a denial-of-service vulnerability, and a fil=
e-overwrite vulnerability.

Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or overwrite files with arbitrary content.

These issues affect TinTin++ and WinTin++ 1.97.9; other versions may also=
 be affected.

8. WinComLPD Total Multiple Buffer Overflow Vulnerabilities and Authentic=
ation Bypass Vulnerability
BugTraq ID: 27614
Remote: Yes
Date Published: 2008-02-04
Relevant URL: http://www.securityfocus.com/bid/27614
Summary:
WinComLPD Total is prone to multiple vulnerabilities, including buffer-ov=
erflow vulnerabilities and an authentication-bypass vulnerability.

Successfully exploiting these issues will allow an attacker to perform un=
authorized actions or execute arbitrary code with the privileges of the u=
ser running the affected application. Failed exploit attempts will likely=
 crash the application.

These issues affect WinComLPD Total 3.0.2.623; other versions may also be=
 vulnerable.

9. Ipswitch FTP Log Server Denial of Service Vulnerability
BugTraq ID: 27612
Remote: Yes
Date Published: 2008-02-04
Relevant URL: http://www.securityfocus.com/bid/27612
Summary:
WS_FTP Log Server shipped with WS_FTP is prone to a remote denial-of-serv=
ice vulnerability.
=20
Successfully exploiting this issue allows remote attackers to crash the a=
ffected application, denying service to legitimate users.

This issue affects WS_FTP running FTP Log Server 7.9.14.0; other versions=
 may also be affected.

10. Titan FTP Server DELE Command Remote Buffer Overflow Vulnerability
BugTraq ID: 27611
Remote: Yes
Date Published: 2008-02-04
Relevant URL: http://www.securityfocus.com/bid/27611
Summary:
Titan FTP Server is prone to a remote buffer-overflow vulnerability becau=
se the application fails to bounds-check user-supplied data before copyin=
g it into an insufficiently sized buffer.=20

An attacker may exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial of service.

This issue affects Titan FTP Server 6.05 build 550; other versions may al=
so be vulnerable.

11. Print Manager Plus PQCore Remote Denial of Service Vulnerability
BugTraq ID: 27604
Remote: Yes
Date Published: 2008-02-04
Relevant URL: http://www.securityfocus.com/bid/27604
Summary:
Print Manager Plus is prone to a remote denial-of-service vulnerability.
=20
Successfully exploiting this issue allows remote attackers to crash affec=
ted servers, potentially causing the application to stop accepting furthe=
r network messages. This may deny service to legitimate users.

The issue affects versions prior to Print Manager Plus 7.0.127.16. Other =
versions may also be affected.

12. Xlight FTP Server LDAP Blank Password Authentication Bypass Vulnerabi=
lity
BugTraq ID: 27602
Remote: Yes
Date Published: 2008-02-04
Relevant URL: http://www.securityfocus.com/bid/27602
Summary:
Xlight FTP Server is prone to an authentication-bypass vulnerability.=20

An attacker can exploit this issue to gain unauthorized access to the aff=
ected application.

This issue affects versions prior to Xlight FTP Server 2.83.

13. IBM DB2 Universal Database Server 8.2 Prior To Fixpak 16 Multiple Loc=
al Vulnerabilities
BugTraq ID: 27596
Remote: No
Date Published: 2008-02-04
Relevant URL: http://www.securityfocus.com/bid/27596
Summary:
IBM DB2 Universal Database Server is prone to multiple local vulnerabilit=
ies, including:

- An unspecified local vulnerability=20
- A local security-bypass vulnerability

Attackers can exploit these issues to compromise the affected application=
, execute arbitrary code within the context of the affected application, =
and bypass certain security restrictions. Other attacks are also possible=
.

These issues affect  versions prior to IBM DB2 Universal Database Server =
8.2 Fixpak 16.

NOTE: Two issues that were previously documented in this BID were given t=
heir own records to better document the details: BID 27681 ('IBM DB2 Univ=
ersal Database DAS Buffer Overflow Vulnerability') and BID 27680 ('IBM DB=
2 Universal Database Server 'db2db' Local Privilege Escalation Vulnerabil=
ity').

14. Ipswitch WS_FTP SFTP Opendir Command Buffer Overflow Vulnerability
BugTraq ID: 27573
Remote: Yes
Date Published: 2008-02-02
Relevant URL: http://www.securityfocus.com/bid/27573
Summary:
Ipswitch WS_FTP is prone to a buffer-overflow vulnerability because the a=
pplication fails to bounds-check user-supplied data before copying it int=
o an insufficiently sized buffer.=20

An attacker may exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial of service.

This issue affects  WS_FTP 6.1.0.0; other versions may also be affected.

15. Titan FTP Server USER/PASS Commands Buffer Overflow Vulnerability
BugTraq ID: 27568
Remote: Yes
Date Published: 2008-02-02
Relevant URL: http://www.securityfocus.com/bid/27568
Summary:
Titan FTP Server is prone to a buffer-overflow vulnerability because the =
application fails to bounds-check user-supplied data before copying it in=
to an insufficiently sized buffer.=20

An attacker may exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers. Failed exploit attempts will re=
sult in a denial of service.

We do not know which versions are affected at this time; we will update t=
his BID as more information emerges.

16. ELOG 'logbook' HTML Injection Vulnerability
BugTraq ID: 27526
Remote: Yes
Date Published: 2008-01-30
Relevant URL: http://www.securityfocus.com/bid/27526
Summary:
ELOG is prone to an HTML-injection vulnerability because the application =
fails to properly sanitize user-supplied input before using it in dynamic=
ally generated content.=20

Attacker-supplied HTML and script code would execute in the context of th=
e affected site, potentially allowing the attacker to steal cookie-based =
authentication credentials or to control how the site is rendered to the =
user; other attacks are also possible.

This issue affects versions prior to ELOG 2.7.2.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #379
http://www.securityfocus.com/archive/88/487457

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat Europe

Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content.  Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com