SecurityFocus Microsoft Newsletter #385

[email protected] 13 Mar 2008 07:33:43 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #385
----------------------------------------

This issue is sponsored by bMighty:

Is Vista Meeting Expectations? =20
New research from InformationWeek reveals what 600 business-technology pr=
ofessionals have to say about Vista's costs, enhancements & adoption chal=
lenges. A $199 value for FREE.
www.bMighty.com
http://www.bmighty.com/drivers/vista.jhtml?cid=3DLSM-sfV


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Integrating More Intelligence into Your IDS, Part 1
       2.Let's Go Crazy
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Cisco User-Changeable Password (UCP) 'CSuserCGI.exe' Multiple R=
emote Vulnerabilities
       2. Microsoft Internet Explorer FTP Cross-Site Command Injection Vu=
lnerability
       3. ManageEngine ServiceDesk Plus 'SolutionSearch.do' Cross-Site Sc=
ripting Vulnerability
       4. ASG-Sentry 7.0.0 Multiple Remote Vulnerabilities
       5. Motorola Timbuktu Pro Multiple Denial of Service Vulnerabilitie=
s
       6. SAP MaxDB sdbstarter Environment Variable Local Privilege Escal=
ation Vulnerability
       7. Acronis Snap Deploy PXE Server TFTP Directory Traversal and Den=
ial of Service Vulnerabilities
       8. Microsoft Excel Conditional Formatting Values Remote Code Execu=
tion Vulnerability
       9. Microsoft Excel Rich Text Value Heap Buffer Overflow Vulnerabil=
ity
       10. Microsoft Excel Formula Parsing Remote Code Execution Vulnerab=
ility
       11. Microsoft Excel Style Record Remote Code Execution Vulnerabili=
ty
       12. MailEnable SMTP EXPN/VRFY Commands Denial of Service Vulnerabi=
lity
       13. Microsoft Outlook Mailto URI Remote Code Execution Vulnerabili=
ty
       14. Microsoft Office File Memory Corruption Vulnerability
       15. MailEnable 3.13 and Prior IMAP Service Multiple Remote Vulnera=
bilities
       16. Microsoft Internet Explorer Combined JavaScript and XML Remote=
 Information Disclosure Vulnerability
       17. SynCE 'vdccm' Daemon Remote Unspecified Denial Of Service Vuln=
erability
       18. Microsoft Office Web Components ActiveX Control DataSource Rem=
ote Code Execution Vulnerability
       19. Microsoft Office Web Components ActiveX Control URL Parsing Re=
mote Code Execution Vulnerability
       20. Microsoft March 2008 Advance Notification Multiple Vulnerabili=
ties
       21. Ruby WEBrick Remote Directory Traversal and Information Disclo=
sure Vulnerabilities
       22. ICQ Toolbar 'toolbaru.dll' ActiveX Control 'GetPropertyById' R=
emote Denial of Service Vulnerability
       23. Microsoft Excel Import Remote Code Execution Vulnerability
       24. Microsoft Excel Data Validation Record Heap Memory Corruption =
Vulnerability
       25. Microsoft Jet Database Engine MDB File Parsing Unspecified Rem=
ote Vulnerability
       26. ICQ Toolbar 'toolbaru.dll' ActiveX Control Remote Denial of Se=
rvice Vulnerability
       27. Timbuktu Pro File Upload and Log Input Manipulation Vulnerabil=
ities
       28. Borland StarTeam Multiple Remote Vulnerabilities
III. MICROSOFT FOCUS LIST SUMMARY
       1. Temp directory is odd
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Integrating More Intelligence into Your IDS, Part 1
By Don Parker and Ryan Wegner=20
The more an intrusion detection system (IDS) knows about the network it i=
s trying to protect, the better it will be able to protect the network. T=
his is the fundamental principle behind target-based intrusion detection,=
 where an IDS knows about the hosts on the network.
http://www.securityfocus.com/infocus/1898

2.Let's Go Crazy
By Mark Rasch
On February 7, 2007 Stephanie Lenz of Gallatzin, Pennsylvania posted an i=
nnocuous video of her 18-month-old son Holden pushing a baby toy while da=
ncing to a barely recognizable song in the background.=20
http://www.securityfocus.com/columnists/467


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Cisco User-Changeable Password (UCP) 'CSuserCGI.exe' Multiple Remote V=
ulnerabilities
BugTraq ID: 28222
Remote: Yes
Date Published: 2008-03-12
Relevant URL: http://www.securityfocus.com/bid/28222
Summary:
Cisco User-Changeable Password (UCP) is prone to multiple remote vulnerab=
ilities. The issues present include multiple cross-site scripting and buf=
fer-overflow vulnerabilities.

Exploiting the cross-site scripting issues may help the attacker steal co=
okie-based authentication credentials and launch other attacks. Exploitin=
g the buffer-overflow vulnerabilities results in remote code-execution in=
 the context of the affected application, facilitating the remote comprom=
ise of affected computers.

These issues affect UCP versions prior to 4.2 when running on the Microso=
ft Windows platform.

The buffer-overflow vulnerabilities are tracked by Cisco Bug ID CSCsl4918=
0. The cross-site scripting issues are tracked by Cisco Bug ID CSCsl49205=
.

2. Microsoft Internet Explorer FTP Cross-Site Command Injection Vulnerabi=
lity
BugTraq ID: 28208
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28208
Summary:
Microsoft Internet Explorer is prone to a vulnerability that occurs becau=
se the application fails to adequately sanitize user-supplied data in FTP=
 URI requests.

An attacker can leverage this issue by enticing an unsuspecting user to f=
ollow a maliciously crafted URI.  Successful exploits will allow attacker=
s to submit arbitrary commands to arbitrary FTP servers on behalf of unsu=
specting users.

This issue affects Internet Explorer 5 and 6; prior versions may also be =
affected.

NOTE: Access to some FTP servers may require valid authentication credent=
ials.

3. ManageEngine ServiceDesk Plus 'SolutionSearch.do' Cross-Site Scripting=
 Vulnerability
BugTraq ID: 28191
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28191
Summary:
ManageEngine ServiceDesk Plus is prone to a cross-site scripting vulnerab=
ility because the application fails to properly sanitize user-supplied in=
put.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.

ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Microsoft Windows is v=
ulnerable; other versions may be affected as well.

4. ASG-Sentry 7.0.0 Multiple Remote Vulnerabilities
BugTraq ID: 28188
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28188
Summary:
ASG-Sentry is prone to multiple remote vulnerabilities:

- A heap-based buffer-overflow vulnerability=20
- A stack-based buffer-overflow vulnerability=20
- A denial-of-service vulnerability=20
- An arbitrary-file-deletion vulnerability

An attacker can exploit these issues to execute arbitrary code within the=
 context of the affected application, crash the affected application, con=
sume all CPU resources, and delete data contained in arbitrary files. Oth=
er attacks are possible.=20

These issues affect ASG-Sentry 7.0.0; other versions may also be affected=
.

5. Motorola Timbuktu Pro Multiple Denial of Service Vulnerabilities
BugTraq ID: 28186
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28186
Summary:
Motorola Timbuktu Pro  is prone to multiple denial-of-service vulnerabili=
ties.=20

Exploiting these issues will allow attackers to crash the affected applic=
ation, denying further service to legitimate users.

6. SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation V=
ulnerability
BugTraq ID: 28185
Remote: No
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28185
Summary:
SAP MaxDB is prone to a local privilege-escalation vulnerability.

Exploiting this issue allows local attackers to execute arbitrary code wi=
th superuser privileges.  This will lead to the complete compromise of an=
 affected computer.

This issue affects MaxDB 7.6.0.37 on both Linux and Solaris platforms.  O=
ther UNIX variants are most likely affected.  Microsoft Windows versions =
are not vulnerable to this issue.

7. Acronis Snap Deploy PXE Server TFTP Directory Traversal and Denial of =
Service Vulnerabilities
BugTraq ID: 28182
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28182
Summary:
Acronis Snap Deploy is prone to a directory-traversal vulnerability and a=
 denial-of-service vulnerability.=20

Exploiting these issues will allow attackers to obtain sensitive informat=
ion or crash the affected application, denying further service to legitim=
ate users.

8. Microsoft Excel Conditional Formatting Values Remote Code Execution Vu=
lnerability
BugTraq ID: 28170
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28170
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

9. Microsoft Excel Rich Text Value Heap Buffer Overflow Vulnerability
BugTraq ID: 28168
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28168
Summary:
Microsoft Excel is prone to a heap-based buffer-overflow vulnerability. T=
his issue occurs because the application fails to perform adequate bounda=
ry-checks on user-supplied data.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

10. Microsoft Excel Formula Parsing Remote Code Execution Vulnerability
BugTraq ID: 28167
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28167
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

11. Microsoft Excel Style Record Remote Code Execution Vulnerability
BugTraq ID: 28166
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28166
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

12. MailEnable SMTP EXPN/VRFY Commands Denial of Service Vulnerability
BugTraq ID: 28154
Remote: Yes
Date Published: 2008-03-09
Relevant URL: http://www.securityfocus.com/bid/28154
Summary:
MailEnable is prone to a remote denial-of-service vulnerability.=20

This issue arises in the SMTP server and may result in a crash of the aff=
ected service.=20

This issue affects all versions of MailEnable Standard Edition, Professio=
nal Edition, and Enterprise Edition.

13. Microsoft Outlook Mailto URI Remote Code Execution Vulnerability
BugTraq ID: 28147
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28147
Summary:
Microsoft Outlook is prone to a remote code-execution vulnerability becau=
se the application fails to adequately validate user-supplied data.

Successfully exploiting this issue will allow attackers to execute arbitr=
ary code with the privileges of the currently logged-in user. This will f=
acilitate the remote compromise of affected computers.

14. Microsoft Office File Memory Corruption Vulnerability
BugTraq ID: 28146
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28146
Summary:
Microsoft Office is prone to a remote memory-corruption vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious Office file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

15. MailEnable 3.13 and Prior IMAP Service Multiple Remote Vulnerabilitie=
s
BugTraq ID: 28145
Remote: Yes
Date Published: 2008-03-07
Relevant URL: http://www.securityfocus.com/bid/28145
Summary:
MailEnable is prone to multiple remote vulnerabilities in the IMAP servic=
e, including:

- Multiple buffer-overflow vulnerabilities.
- Multiple denial-of-service vulnerabilities due to a NULL-pointer except=
ion.

An attacker may leverage these issues to execute arbitrary code in the co=
ntext of the running application or to crash the application, causing a d=
enial of service.

These issues affect MailEnable 3.13; other versions may also be vulnerabl=
e.

16. Microsoft Internet Explorer Combined JavaScript and XML Remote Inform=
ation Disclosure Vulnerability
BugTraq ID: 28143
Remote: Yes
Date Published: 2008-03-07
Relevant URL: http://www.securityfocus.com/bid/28143
Summary:
Microsoft Internet Explorer is prone to a remote information-disclosure v=
ulnerability because of a flaw in the interaction between JavaScript and =
XML processing in Internet Explorer.

To exploit this issue, an attacker must entice an unsuspecting user to vi=
sit a malicious website.

Successfully exploiting this issue allows remote attackers to gain access=
 to the first line of arbitrary files located on computers running the vu=
lnerable application.

17. SynCE 'vdccm' Daemon Remote Unspecified Denial Of Service Vulnerabili=
ty
BugTraq ID: 28141
Remote: Yes
Date Published: 2008-03-07
Relevant URL: http://www.securityfocus.com/bid/28141
Summary:
SynCE 'vdccm' Daemon is prone to a denial-of-service vulnerability.

Remote attackers can exploit this issue to deny service to legitimate use=
rs.

This issue affects versions prior to SynCE 'vdccm' Daemon 0.10.1.

18. Microsoft Office Web Components ActiveX Control DataSource Remote Cod=
e Execution Vulnerability
BugTraq ID: 28136
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28136
Summary:
Microsoft Office Web Components is prone to a remote code-execution vulne=
rability.

An attacker may exploit this issue by enticing victims into opening a mal=
iciously crafted HTML document.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts will likely result =
in denial-of-service conditions.

19. Microsoft Office Web Components ActiveX Control URL Parsing Remote Co=
de Execution Vulnerability
BugTraq ID: 28135
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28135
Summary:
Microsoft Office Web Components is prone to a remote code-execution vulne=
rability.

An attacker may exploit this issue by enticing victims into opening a mal=
iciously crafted HTML document.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts will likely result =
in denial-of-service conditions.

20. Microsoft March 2008 Advance Notification Multiple Vulnerabilities
BugTraq ID: 28124
Remote: Yes
Date Published: 2008-03-06
Relevant URL: http://www.securityfocus.com/bid/28124
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing four security bulletins on March 11, 2008. The highest severity rati=
ng for these issues is 'Critical'.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

Individual records for these issues will be created when the bulletins ar=
e released.

21. Ruby WEBrick Remote Directory Traversal and Information Disclosure Vu=
lnerabilities
BugTraq ID: 28123
Remote: Yes
Date Published: 2008-03-06
Relevant URL: http://www.securityfocus.com/bid/28123
Summary:
Ruby's WEBrick server is prone to remote directory-traversal and informat=
ion-disclosure vulnerabilities.

Successfully exploiting these issues allows remote attackers to access th=
e contents of arbitrary files. Information harvested may aid in further a=
ttacks.

These issues affect only operating systems that allow backslash (\) chara=
cters as path separators and operating systems that use case-insensitive =
filenames. This exposes Microsoft Windows and Apple Mac OS X operating sy=
stems to attack.

22. ICQ Toolbar 'toolbaru.dll' ActiveX Control 'GetPropertyById' Remote D=
enial of Service Vulnerability
BugTraq ID: 28118
Remote: Yes
Date Published: 2008-03-06
Relevant URL: http://www.securityfocus.com/bid/28118
Summary:
ICQ Toolbar 'toolbaru.dll' ActiveX control is prone to a denial-of-servic=
e vulnerability.

An attacker can exploit this issue to trigger denial-of-service condition=
s in Internet Explorer or other applications that use the vulnerable Acti=
veX control.

This issue affects ICQ Toolbar 2.3; other versions may also be affected.

23. Microsoft Excel Import Remote Code Execution Vulnerability
BugTraq ID: 28095
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28095
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

24. Microsoft Excel Data Validation Record Heap Memory Corruption Vulnera=
bility
BugTraq ID: 28094
Remote: Yes
Date Published: 2008-03-11
Relevant URL: http://www.securityfocus.com/bid/28094
Summary:
Microsoft Excel is prone to a heap memory-corruption vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file ('.xls').

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.

25. Microsoft Jet Database Engine MDB File Parsing Unspecified Remote Vul=
nerability
BugTraq ID: 28087
Remote: Yes
Date Published: 2008-03-03
Relevant URL: http://www.securityfocus.com/bid/28087
Summary:
Microsoft Jet Database Engine is prone to an unspecifed security vulnerab=
ility.

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of a user running the application. Successful exploits wi=
ll compromise the affected application and possibly the underlying comput=
er. Failed attacks will likely cause denial-of-service conditions.

26. ICQ Toolbar 'toolbaru.dll' ActiveX Control Remote Denial of Service V=
ulnerability
BugTraq ID: 28086
Remote: Yes
Date Published: 2008-03-04
Relevant URL: http://www.securityfocus.com/bid/28086
Summary:
ICQ Toolbar 'toolbaru.dll' ActiveX control is prone to a denial-of-servic=
e vulnerability.

An attacker can exploit this issue to trigger denial-of-service condition=
s in Internet Explorer or other applications that use the vulnerable Acti=
veX control.

This issue affects ICQ Toolbar 2.3 Beta; other versions may also be affec=
ted.

27. Timbuktu Pro File Upload and Log Input Manipulation Vulnerabilities
BugTraq ID: 28081
Remote: Yes
Date Published: 2008-03-10
Relevant URL: http://www.securityfocus.com/bid/28081
Summary:
Timbuktu Pro is prone to an arbitrary-file-upload vulnerability and a vul=
nerability that allows attackers to disrupt the logging of events.

An attacker can exploit these issues to upload arbitrary files and preven=
t the logging of events. This may lead to other attacks.

Timbuktu Pro 8.6.5 for Windows is vulnerable; other versions running on d=
ifferent platforms may also be affected.

The file-upload vulnerability may be related to BID 25453 (Motorola Timbu=
ktu Pro Directory Traversal Vulnerability).

28. Borland StarTeam Multiple Remote Vulnerabilities
BugTraq ID: 28080
Remote: Yes
Date Published: 2008-03-03
Relevant URL: http://www.securityfocus.com/bid/28080
Summary:
Borland StarTeam is prone to multiple issues, including multiple integer-=
overflow vulnerabilities, a heap-overflow vulnerability, and a denial-of-=
service vulnerability.

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary machine code in the context of vulnerable server processes. Thes=
e issues may facilitate the remote compromise of affected computers. Atta=
ckers may also trigger denial-of-service conditions.

NOTE: The StarTeam MPX vulnerabilities may actually be related to a TIBCO=
 SmartSocket DLL, but this has not been confirmed. We may update this BID=
 as more information emerges.

Borland StarTeam Server 2008 and MPX products are vulnerable to these iss=
ues; other versions may also be affected.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Temp directory is odd
http://www.securityfocus.com/archive/88/489429

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by bMighty:

Is Vista Meeting Expectations? =20
New research from InformationWeek reveals what 600 business-technology pr=
ofessionals have to say about Vista's costs, enhancements & adoption chal=
lenges. A $199 value for FREE.
www.bMighty.com
http://www.bmighty.com/drivers/vista.jhtml?cid=3DLSM-sfV