SecurityFocus Microsoft Newsletter #390
[email protected] 16 Apr 2008 22:10:51 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #390
----------------------------------------
This issue is sponsored by Blackhat
Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts.=20
Featuring 40 hands-on training courses and 80 Briefings presentations wit=
h lots of new content and new tools. =20
Network with 4,000 delegates from 50 nations. =20
Visit product displays by 30 top sponsors in a relaxed setting. =20
www.blackhat.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.On the Border
2.Catch Them if You can
II. MICROSOFT VULNERABILITY SUMMARY
1. ICQ 'Personal Status Manager' Remote Buffer Overflow Vulnerabil=
ity
2. RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer O=
verflow Vulnerability
3. Nero MediaHome NMMediaServer.EXE Remote Denial of Service Vulne=
rability
4. XM Easy Personal FTP Server 'PORT and 'XCWD' Multiple Remote De=
nial of Service Vulnerabilities
5. ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow V=
ulnerability
6. Trillian DTD File XML Parser Buffer Overflow Vulnerability
7. Symantec Altiris Deployment Solution AClient Password Disclosur=
e Vulnerability
8. Microsoft SharePoint Server Picture Source HTML Injection Vulne=
rability
9. HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulne=
rability
10. Microsoft Internet Explorer Header Handling 'res://' Informati=
on Disclosure Vulnerability
11. Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remot=
e Buffer Overflow Vulnerability
12. Microsoft Project Resource Memory Allocation Remote Code Execu=
tion Vulnerability
13. Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnera=
bility
14. Microsoft Windows GDI 'CreateDIBPatternBrushPt' Function Heap =
Overflow Vulnerability
15. Microsoft Windows GDI Stack Overflow Vulnerability
16. Microsoft Visio Memory Validation Remote Code Execution Vulner=
ability
17. Microsoft Visio Object Header Remote Code Execution Vulnerabil=
ity
18. Microsoft Windows Kernel Usermode Callback Local Privilege Esc=
alation Vulnerability
19. Microsoft Windows DNS Client Service Response Spoofing Vulnera=
bility
20. Microsoft Internet Explorer Data Stream Handling Remote Code E=
xecution Vulnerability
21. Microsoft VBScript and JScript Scripting Engines Remote Code E=
xecution Vulnerability
22. Autonomy KeyView Module Multiple Buffer Overflow Vulnerabiliti=
es
III. MICROSOFT FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.On the Border
By Mark Rasch
Recently, I was going through an airport with my shoes, coat, jacket, and=
belt off as well as with my carry-on bag, briefcase, and laptop all sepa=
rated for easy inspection. I was heading through security at the Washingt=
on D.C., Ronald Reagan National Airport in Arlington, Virginia, or "Natio=
nal" as we locals call it. As I passed through the new magnetometer which=
gently puffed air all over my body -- which to me seems to be a cross be=
tween a glaucoma test and Marilyn Monroe in Gentlemen Prefer Blondes -- a=
TSA employee absent-mindedly asked if he could "inspect" my laptop compu=
ter. While the inspection was cursory, the situation immediately gave me =
pause: What was in my laptop anyway?
http://www.securityfocus.com/columnists/469
2.Catch Them if You Can
By Don Parker
High-profile network security breaches have proliferated over the past fe=
w years. While many "breaches" consist of lost data or a stolen laptop, t=
rue breaches -- where a online attacker compromises a network and removes=
data -- have become very common
http://www.securityfocus.com/columnists/468
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. ICQ 'Personal Status Manager' Remote Buffer Overflow Vulnerability
BugTraq ID: 28803
Remote: Yes
Date Published: 2008-04-16
Relevant URL: http://www.securityfocus.com/bid/28803
Summary:
ICQ is prone to a remote buffer-overflow vulnerability because the applic=
ation fails to perform boundary checks before copying user-supplied data =
into sensitive process buffers.
A remote attacker may execute arbitrary code in the context of the affect=
ed application. Failed exploit attempts will result in a denial of servic=
e.=20
=20
This issue affects ICQ 6 build 6043; other versions may also be vulnerabl=
e.
2. RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow=
Vulnerability
BugTraq ID: 28783
Remote: Yes
Date Published: 2008-04-15
Relevant URL: http://www.securityfocus.com/bid/28783
Summary:
ClamAV is prone to a heap-based buffer-overflow vulnerability because it =
fails to properly verify user-supplied data.=20
Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the vu=
lnerable 'libclamav' library. Failed exploit attempts will likely cause d=
enial-of-service conditions.
ClamAV 0.92 and 0.92.1 are vulnerable to this issue; other versions may a=
lso be affected.
NOTE: This BID is being retired because it is a duplicate of BID 28756.
3. Nero MediaHome NMMediaServer.EXE Remote Denial of Service Vulnerabilit=
y
BugTraq ID: 28775
Remote: Yes
Date Published: 2008-04-14
Relevant URL: http://www.securityfocus.com/bid/28775
Summary:
Nero MediaHome is prone to a remote denial-of-service vulnerability becau=
se the application fails to handle exceptional conditions.=20
An attacker can exploit this issue to crash the affected application, den=
ying further service to legitimate users.=20
This issue affects Nero MediaHome 3.3.3.0. Other versions may also be aff=
ected.
4. XM Easy Personal FTP Server 'PORT and 'XCWD' Multiple Remote Denial of=
Service Vulnerabilities
BugTraq ID: 28759
Remote: Yes
Date Published: 2008-04-14
Relevant URL: http://www.securityfocus.com/bid/28759
Summary:
XM Easy Personal FTP Server is prone to multiple remote denial-of-service=
vulnerabilities.
These issues allow remote attackers to crash affected FTP servers, denyin=
g service to legitimate users. Given the nature of these issues, attacker=
s may also be able to execute arbitrary code, but this has not been confi=
rmed.
XM Easy Personal FTP Server 5.4.0 is vulnerable; other versions may also =
be affected.
5. ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerab=
ility
BugTraq ID: 28756
Remote: Yes
Date Published: 2008-04-14
Relevant URL: http://www.securityfocus.com/bid/28756
Summary:
ClamAV is prone to a heap-based buffer-overflow vulnerability because it =
fails to properly verify user-supplied data.=20
Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the vu=
lnerable 'libclamav' library. Failed exploit attempts will likely cause d=
enial-of-service conditions.
ClamAV 0.92 and 0.92.1 are vulnerable to this issue; other versions may a=
lso be affected.
6. Trillian DTD File XML Parser Buffer Overflow Vulnerability
BugTraq ID: 28747
Remote: Yes
Date Published: 2008-04-11
Relevant URL: http://www.securityfocus.com/bid/28747
Summary:
Trillian is prone to a buffer-overflow vulnerability because it fails to =
perform adequate boundary checks on user-supplied input.
To exploit this issue, an attacker must entice an unsuspecting user to lo=
ad a malicious '.dtd' file. Successfully exploiting this issue may allow =
remote attackers to execute arbitrary code with SYSTEM-level privileges. =
Failed exploit attempts will cause denial-of-service conditions.=20
Trillian 3.1.9.0 Basic is vulnerable; other versions may also be affected=
.
7. Symantec Altiris Deployment Solution AClient Password Disclosure Vulne=
rability
BugTraq ID: 28707
Remote: No
Date Published: 2008-04-10
Relevant URL: http://www.securityfocus.com/bid/28707
Summary:
Symantec Altiris Deployment Solution AClient is prone to a local password=
-disclosure vulnerability because of a design error.
=20
Exploiting this issue may allow a local attacker to access unencrypted pa=
sswords, potentially allowing them to access the application's administra=
tive interface in an unauthorized manner. This can facilitate a complete =
compromise of affected computers.
This issue affects versions prior to Altiris Deployment Solution 6.9.164.
8. Microsoft SharePoint Server Picture Source HTML Injection Vulnerabilit=
y
BugTraq ID: 28706
Remote: Yes
Date Published: 2008-04-09
Relevant URL: http://www.securityfocus.com/bid/28706
Summary:
Microsoft SharePoint Server is prone to an HTML-injection vulnerability b=
ecause it fails to sufficiently sanitize user-supplied input data. Note t=
hat to perform attacks, an attacker requires access to a user account wit=
h sufficient privileges to edit pages.
Exploiting this issue may allow the attacker to execute HTML and script c=
ode in the context of the affected site, to steal cookie-based authentica=
tion credentials, or to control how the site is rendered to the user; oth=
er attacks are also possible.
=20
Microsoft SharePoint Server 2.0 is vulnerable; other versions may also be=
affected.
9. HP OpenView Network Node Manager 'ovspmd' Buffer Overflow Vulnerabilit=
y
BugTraq ID: 28689
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28689
Summary:
HP OpenView Network Node Manager is prone to a buffer-overflow vulnerabil=
ity.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the Network Node Manager process. This faci=
litates the remote compromise of affected computers.
Network Node Manager 7.53 running on Microsoft Windows is affected by thi=
s issue; other versions and platforms may also be vulnerable.
10. Microsoft Internet Explorer Header Handling 'res://' Information Disc=
losure Vulnerability
BugTraq ID: 28667
Remote: Yes
Date Published: 2008-04-07
Relevant URL: http://www.securityfocus.com/bid/28667
Summary:
Microsoft Internet Explorer is prone to an information-disclosure vulnera=
bility.=20
An attacker can exploit this issue to obtain potentially sensitive inform=
ation from the local computer. Information obtained may aid in further at=
tacks.
This issue affects Internet Explorer 7. Reportedly, Internet Explorer 8 i=
s not vulnerable, but this has not been confirmed.=20
This issue may be related to the vulnerability discussed in BID 28581 (Mi=
crosoft Internet Explorer 'ieframe.dll' Script Injection Vulnerability).
11. Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffe=
r Overflow Vulnerability
BugTraq ID: 28662
Remote: Yes
Date Published: 2008-04-07
Relevant URL: http://www.securityfocus.com/bid/28662
Summary:
Tumbleweed SecureTransport is prone to a buffer-overflow vulnerability be=
cause it fails to perform adequate boundary checks on user-supplied input=
.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of an application using the ActiveX control (typically Internet Explor=
er). Failed attacks will likely cause denial-of-service conditions.
12. Microsoft Project Resource Memory Allocation Remote Code Execution Vu=
lnerability
BugTraq ID: 28607
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28607
Summary:
Microsoft Project is prone to a remote code-execution vulnerability.=20
An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Failed exploit attempts will likely resul=
t in denial-of-service conditions.
13. Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability
BugTraq ID: 28606
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28606
Summary:
Microsoft 'hxvz.dll' ActiveX control is prone to a remote memory-corrupti=
on vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.
14. Microsoft Windows GDI 'CreateDIBPatternBrushPt' Function Heap Overflo=
w Vulnerability
BugTraq ID: 28571
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28571
Summary:
Microsoft Windows is prone to a heap-based overflow vulnerability that re=
sides in the GDI graphics library and can be triggered by a malformed EMF=
or WMF image file.
A successful exploit of this vulnerability can allow a remote attacker to=
completely compromise the affected computer.
15. Microsoft Windows GDI Stack Overflow Vulnerability
BugTraq ID: 28570
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28570
Summary:
Microsoft Windows is prone to a stack-based overflow vulnerability that r=
esides in the GDI graphics library and can be triggered by a malformed EM=
F image file.
=20
A successful exploit of this vulnerability can allow a remote attacker =
to completely compromise the affected computer.
16. Microsoft Visio Memory Validation Remote Code Execution Vulnerability
BugTraq ID: 28556
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28556
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
it fails to adequately handle user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context=
of the user running the application. Failed exploit attempts will result=
in a denial-of-service condition.
17. Microsoft Visio Object Header Remote Code Execution Vulnerability
BugTraq ID: 28555
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28555
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
it fails to adequately handle user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context=
of the user running the application. Failed exploit attempts will result=
in a denial-of-service condition.
18. Microsoft Windows Kernel Usermode Callback Local Privilege Escalation=
Vulnerability
BugTraq ID: 28554
Remote: No
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28554
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability.=
=20
The vulnerability resides in the Windows kernel. A locally logged-in user=
can exploit this issue to gain kernel-level access to the operating syst=
em.
19. Microsoft Windows DNS Client Service Response Spoofing Vulnerability
BugTraq ID: 28553
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28553
Summary:
Microsoft Windows operating systems are prone to a vulnerability that let=
s attackers spoof DNS clients. This issue occurs because the software fai=
ls to employ properly secure random numbers when creating DNS transaction=
IDs.
Successfully exploiting this issue allows remote attackers to spoof DNS r=
eplies, allowing them to redirect network traffic and to launch man-in-th=
e-middle attacks.
20. Microsoft Internet Explorer Data Stream Handling Remote Code Executio=
n Vulnerability
BugTraq ID: 28552
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28552
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity because it fails to adequately handle certain user-supplied data.
Attackers can leverage this issue to execute arbitrary code with the priv=
ileges of the application. Successful exploits will compromise affected c=
omputers. Failed attacks may cause denial-of-service conditions.
21. Microsoft VBScript and JScript Scripting Engines Remote Code Executio=
n Vulnerability
BugTraq ID: 28551
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28551
Summary:
Microsoft VBScript and JScript are prone to a remote code-execution vulne=
rability because they fail to adequately handle user-supplied input.
Attackers can leverage this issue by enticing an unsuspecting user to vie=
w a malicious web document. Successful exploits would allow arbitrary cod=
e to run with the privileges of the victim.
These versions are affected:
VBScript 5.6 and earlier=20
JScript 5.6 and earlier
22. Autonomy KeyView Module Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 28454
Remote: Yes
Date Published: 2008-04-08
Relevant URL: http://www.securityfocus.com/bid/28454
Summary:
Autonomy KeyView module is prone to multiple stack- and heap-based buffer=
-overflow vulnerabilities because it fails to perform adequate boundary c=
hecks on user-supplied data before copying it to insufficiently sized buf=
fers.
Exploiting these issues will allow an attacker to corrupt memory and to c=
ause denial-of-service conditions or potentially to execute arbitrary cod=
e in the context of the application using the module.
Multiple products using the KeyView module are affected.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Blackhat
Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts.=20
Featuring 40 hands-on training courses and 80 Briefings presentations wit=
h lots of new content and new tools. =20
Network with 4,000 delegates from 50 nations. =20
Visit product displays by 30 top sponsors in a relaxed setting. =20
www.blackhat.com