SecurityFocus Microsoft Newsletter #384

[email protected] 5 Mar 2008 22:35:48 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #384
----------------------------------------

This issue is Sponsored by: Black Hat Europe

Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content.  Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.A Guide to Different Kinds of Honeypots
       2.The Laws of Full Disclosure
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Microsoft Jet Database Engine MDB File Parsing Unspecified Remo=
te Vulnerability
       2. ICQ Toolbar 'toolbaru.dll' ActiveX Control Remote Denial of Ser=
vice Vulnerability
       3. Borland StarTeam Multiple Remote Vulnerabilities
       4. Wireshark 0.99.7 Multiple Denial of Service Vulnerabilities
       5. activePDF Server Packet Processing Remote Heap Overflow Vulnera=
bility
       6. RETIRED: Microsoft Word Unspecified Remote Code Execution Vulne=
rability
       7. Symantec Backup Exec Scheduler ActiveX Control Multiple Arbitra=
ry File Overwrite Vulnerabilities
       8. Symantec Decomposer RAR File Remote Buffer Overflow Vulnerabili=
ty
       9. Symantec Decomposer Resource Consumption Denial of Service Vuln=
erability
       10. Symantec Backup Exec Scheduler ActiveX Control Multiple Stack =
Based Buffer Overflow Vulnerabilities
III. MICROSOFT FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.A Guide to Different Kinds of Honeypots
Honeypots come in many shapes and sizes and are available to mimic lots o=
f different kinds of applications and protocols. We shall take the defini=
tion of a honeypot as "a security resource whose value lies in being prob=
ed, attacked, or compromised"[Spitzner02]. That is, a honeypot is a syste=
m we can monitor to observe how attackers behave, a system which is desig=
ned to lure attackers away from more valuable systems and/or a system whi=
ch is designed to provide early warning of an intrusion to the target net=
work. A honeypot may be used for all three applications at the same time.
http://www.securityfocus.com/infocus/1897

2.The Laws of Full Disclosure
By Federico Biancuzzi
Full disclosure has a long tradition in the security community worldwide,=
 yet different European countries have different views on the legality of=
 vulnerability research. SecurityFocus contributor Federico Biancuzzi inv=
estigates the subject of full disclosure and the law by interviewing lawy=
ers from twelve EU countries: Belgium, Denmark, Finland, France, Germany,=
Greece, Hungary, Ireland, Italy, Poland, Romania, and the UK.
http://www.securityfocus.com/columnists/466


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Microsoft Jet Database Engine MDB File Parsing Unspecified Remote Vuln=
erability
BugTraq ID: 28087
Remote: Yes
Date Published: 2008-03-03
Relevant URL: http://www.securityfocus.com/bid/28087
Summary:
Microsoft Jet Database Engine is prone to an unspecifed security vulnerab=
ility.

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of a user running the application. Successful exploits wi=
ll compromise the affected application and possibly the underlying comput=
er. Failed attacks will likely cause denial-of-service conditions.

2. ICQ Toolbar 'toolbaru.dll' ActiveX Control Remote Denial of Service Vu=
lnerability
BugTraq ID: 28086
Remote: Yes
Date Published: 2008-03-04
Relevant URL: http://www.securityfocus.com/bid/28086
Summary:
ICQ Toolbar 'toolbaru.dll' ActiveX control is prone to a denial-of-servic=
e vulnerability.

An attacker can exploit this issue to trigger denial-of-service condition=
s in Internet Explorer or other applications that use the vulnerable Acti=
veX control.

This issue affects ICQ Toolbar 2.3 Beta; other versions may also be affec=
ted.

3. Borland StarTeam Multiple Remote Vulnerabilities
BugTraq ID: 28080
Remote: Yes
Date Published: 2008-03-03
Relevant URL: http://www.securityfocus.com/bid/28080
Summary:
Borland StarTeam is prone to multiple issues, including multiple integer-=
overflow vulnerabilities, a heap-overflow vulnerability, and a denial-of-=
service vulnerability.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of vulnerable server processes. Thes=
e issues may facilitate the remote compromise of affected computers. Atta=
ckers may also trigger denial-of-service conditions.

NOTE: The StarTeam MPX vulnerabilities may actually be related to a TIBCO=
 SmartSocket DLL, but this has not been confirmed. We may update this BID=
 as more information emerges.

Borland StarTeam Server 2008 and MPX products are vulnerable to these iss=
ues; other versions may also be affected.

4. Wireshark 0.99.7 Multiple Denial of Service Vulnerabilities
BugTraq ID: 28025
Remote: Yes
Date Published: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/28025
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.

Exploiting these issues may allow attackers to cause crashes and deny ser=
vice to legitimate users of the application. Attackers may be able to lev=
erage some of these vulnerabilities to execute arbitrary code, but this h=
as not been confirmed.

Wireshark 0.6.0 to 0.99.7 are affected.

5. activePDF Server Packet Processing Remote Heap Overflow Vulnerability
BugTraq ID: 28013
Remote: Yes
Date Published: 2008-02-27
Relevant URL: http://www.securityfocus.com/bid/28013
Summary:
activePDF Server is prone to a remote heap-overflow vulnerability because=
 it fails to perform adequate boundary checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the affected application. Failed attacks will likely cause denial-of=
-service conditions.

This issue affects activePDF Server 3.8.4 and 3.8.5.14; other versions ma=
y be affected as well.

6. RETIRED: Microsoft Word Unspecified Remote Code Execution Vulnerabilit=
y
BugTraq ID: 28011
Remote: Yes
Date Published: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/28011
Summary:
Microsoft Word is prone to an unspecified remote code-execution vulnerabi=
lity.

Very few details are available regarding this issue. We will update this =
BID as more information emerges.

 It is unknown at this time which specific versions of the application ar=
e affected.

NOTE: This BID is being retired because the vulnerability is already cove=
red in BID  23804  (Microsoft Word Array Remote Code Execution Vulnerabil=
ity).

7. Symantec Backup Exec Scheduler ActiveX Control Multiple Arbitrary File=
 Overwrite Vulnerabilities
BugTraq ID: 28008
Remote: Yes
Date Published: 2008-02-28
Relevant URL: http://www.securityfocus.com/bid/28008
Summary:
Symantec Backup Exec is prone to multiple vulnerabilities that allow atta=
ckers overwrite arbitrary files.

An attacker can exploit these issues by enticing an unsuspecting victim t=
o view a malicious HTML page.=20

Successfully exploiting these issues will allow the attacker to corrupt a=
nd overwrite arbitrary files on the victim's computer in the context of t=
he vulnerable application using the ActiveX control (typically Internet E=
xplorer).

8. Symantec Decomposer RAR File Remote Buffer Overflow Vulnerability
BugTraq ID: 27913
Remote: Yes
Date Published: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27913
Summary:
Symantec Decomposer is prone to a remote buffer-overflow vulnerability be=
cause the application fails to properly bounds-check user-supplied input =
before copying it to an insufficiently sized memory buffer.

An attacker may exploit this issue to execute arbitrary machine code with=
 the privileges of the user running the affected application. Failed expl=
oit attempts will result in a denial-of-service condition.

The following products are affected:

- Symantec Scan Engine 5.1.4.24 and prior
- Symantec AntiVirus Scan Engine 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS ISA 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS SharePoint 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Messaging 4.3.16.39 and prior
- Symantec AntiVirus for Network Attached Storage 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Clearswift 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Caching 4.3.16.39 and prior
- Symantec AntiVirus/Filtering for Domino MPE(AIX, Linux, Solaris) prior =
to 3.2.2
- Symantec Mail Security for Microsoft Exchange 4.6.5.12 and prior as wel=
l as 5.0.4.363 and prior

9. Symantec Decomposer Resource Consumption Denial of Service Vulnerabili=
ty
BugTraq ID: 27911
Remote: Yes
Date Published: 2008-02-26
Relevant URL: http://www.securityfocus.com/bid/27911
Summary:
Symantec Decomposer is prone to a denial-of-service vulnerability because=
 it fails to adequately parse certain user-supplied input.

Attackers can exploit this issue to exhaust memory resources and cause de=
nial-of-service conditions.

The following products are affected:
- Symantec Scan Engine  5.1.4.24 and prior
- Symantec AntiVirus Scan Engine 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS ISA 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for MS SharePoint 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Messaging 4.3.16.39 and prior
- Symantec AntiVirus for Network Attached Storage 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Clearswift 4.3.16.39 and prior
- Symantec AntiVirus Scan Engine for Caching  4.3.16.39 and prior
- Symantec AntiVirus/Filtering for Domino MPE(AIX, Linux, Solaris)  prior=
 to 3.2.2
- Symantec Mail Security for Microsoft Exchange 4.6.5.12 and prior as wel=
l as 5.0.4.363 and prior.

10. Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based B=
uffer Overflow Vulnerabilities
BugTraq ID: 26904
Remote: Yes
Date Published: 2008-02-28
Relevant URL: http://www.securityfocus.com/bid/26904
Summary:
An ActiveX control in the scheduler component of Symantec Backup Exec is =
prone to multiple stack-based buffer-overflow vulnerabilities because the=
 application fails to perform adequate boundary checks on user-supplied d=
ata.=20

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
 (typically Internet Explorer). Failed exploit attempts likely result in =
denial-of-service conditions.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by: Black Hat Europe

Attend Black Hat Europe, March 25-28, Amsterdam, Europe's premier technic=
al event for ICT security experts. Featuring hands-on training courses an=
d Briefings presentations with lots of new content.  Network with 400+ de=
legates from 30 nations and review products by leading vendors in a relax=
ed setting. Black Hat Europe is supported by most leading European infose=
c associations. =20
www.blackhat.com