SecurityFocus Microsoft Newsletter #391

[email protected] 23 Apr 2008 20:47:42 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #391
----------------------------------------

This issue is sponsored by HP

Top 10 security vulnerabilities in .NET configuration files: are your web=
 applications vulnerable?
Even the smallest opening in your web application layer can grant full ac=
cess to an intruder. A hacker armed with nothing more than a web browser =
and knowledge of basic programming techniques can steal your most sensiti=
ve information by taking advantage of openings that exist in the the web =
server, application configuration and source code. This free white paper,=
 from HP Software, discusses the 10 most common .NET application configur=
ation mistakes, the devastating effects those mistakes can have as well a=
s best practices for managing configuration files to prevent attacks.
https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=3DdownloadPDF&zn=
=3Dbto&cp=3D54_4012_100__&caid=3D14532&jumpid=3Dex_r11374_us/en/large/tsg=
/Top10_Security_Vulnerabilities_WP_Newsletter/3-1A4COJW_3-ULBT8Q/20080429=
&origin_id=3D3-1A4COJW


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Just Who's Being Exploited?
       2.On the Border
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Apple Safari 3.1.1 For Windows Multiple Denial of Service and S=
poofing Vulnerabilities
       2. Foxit Reader Multiple Remote Memory Corruption Vulnerabilities
       3. Microsoft 'HeartbeatCtl' ActiveX Control Remote Buffer Overflow=
 Vulnerability
       4. SubEdit Player Subtitle File Remote Buffer Overflow Vulnerabili=
ty
       5. IBM DB2 Universal Database ADMIN_SP_C and ADMIN_SP_C2 Prodecure=
s Remote Code Execution Vulnerability
       6. IBM DB2 'NNSTAT' Procedure Arbitrary File Overwrite Vulnerabili=
ty
       7. IBM DB2 Universal Database JAR File Processing Multiple Denial =
of Service Vulnerabilities
       8. Microsoft Windows SeImpersonatePrivilege Local Privilege Escala=
tion Vulnerability
       9. ImageMagick Malformed PCX File Heap Overflow Vulnerability
       10. ImageMagick Malformed XCF File Heap Overflow Vulnerability
       11. Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code E=
xecution Vulnerability
       12. Apple Safari WebKit JavaScript Regular Expression Repetition C=
ounts Buffer Overflow Vulnerability
       13. Apple Safari WebKit URI Handling Cross-Site Scripting Vulnerab=
ility
       14. Apple Safari File Download Remote Memory Corruption Vulnerabil=
ity
       15. ICQ 'Personal Status Manager' Remote Buffer Overflow Vulnerabi=
lity
       16. ClamAV 'libclamav/pe.c' WWPACK File Heap Based Buffer Overflow=
 Vulnerability
       17. RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer =
Overflow Vulnerability
       18. Nero MediaHome NMMediaServer.EXE Remote Denial of Service Vuln=
erability
       19. XM Easy Personal FTP Server 'PORT and 'XCWD' Multiple Remote D=
enial of Service Vulnerabilities
       20. ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow =
Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #390
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Just Who's Being Exploited?
By Jamie Reid
Last month's revelation that Tipping Point paid out a prize of $10,000 an=
d a new laptop (MSRP: about $2000) at the CanSecWest conference, for the =
privilege of being the exclusive licensor of a heretofore unpublished vul=
nerability in Apple's Safari web browser to researcher, Charles Miller of=
 Independent Security Evaluators, may lend some credence to this adage.
http://www.securityfocus.com/columnists/470

2.On the Border
By Mark Rasch
Recently, I was going through an airport with my shoes, coat, jacket, and=
 belt off as well as with my carry-on bag, briefcase, and laptop all sepa=
rated for easy inspection. I was heading through security at the Washingt=
on D.C., Ronald Reagan National Airport in Arlington, Virginia, or "Natio=
nal" as we locals call it. As I passed through the new magnetometer which=
 gently puffed air all over my body -- which to me seems to be a cross be=
tween a glaucoma test and Marilyn Monroe in Gentlemen Prefer Blondes -- a=
 TSA employee absent-mindedly asked if he could "inspect" my laptop compu=
ter. While the inspection was cursory, the situation immediately gave me =
pause: What was in my laptop anyway?
http://www.securityfocus.com/columnists/469


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing=
 Vulnerabilities
BugTraq ID: 28891
Remote: Yes
Date Published: 2008-04-22
Relevant URL: http://www.securityfocus.com/bid/28891
Summary:
Apple Safari is prone to multiple remote vulnerabilities, including:

- A denial-of-service vulnerability caused by a write-access violation.=20
- A denial-of-service vulnerability caused by a read-access violation.
- A vulnerability that allows attackers to spoof the content contained in=
 the address bar.=20

An attacker can exploit these issues to crash the affected application or=
 cause the victim to interact with the attacker's malicious site.

This issue affects Apple Safari 3.1.1 for Windows; other versions may als=
o be affected.

2. Foxit Reader Multiple Remote Memory Corruption Vulnerabilities
BugTraq ID: 28890
Remote: Yes
Date Published: 2008-04-22
Relevant URL: http://www.securityfocus.com/bid/28890
Summary:
Foxit Reader is prone to two remote memory-corruption vulnerabilities bec=
ause it fails to handle specially crafted PDF files.

Remote attackers may be able to execute code, but this has not been confi=
rmed. Failed exploit attempts will crash the application, denying service=
 to legitimate users.
 =20
Foxit Reader 2.2 is vulnerable; other versions may also be affected.

3. Microsoft 'HeartbeatCtl' ActiveX Control Remote Buffer Overflow Vulner=
ability
BugTraq ID: 28882
Remote: Yes
Date Published: 2008-04-21
Relevant URL: http://www.securityfocus.com/bid/28882
Summary:
Microsoft 'HeartbeatCtl' ActiveX control is prone to a remote buffer-over=
flow vulnerability.

Remote attackers can exploit this issue to execute arbitrary code in the =
context of the application using the ActiveX control (typically Internet =
Explorer). Successful exploits will compromise the application and possib=
ly the underlying computer. Failed attacks will cause denial-of-service c=
onditions.

4. SubEdit Player Subtitle File Remote Buffer Overflow Vulnerability
BugTraq ID: 28858
Remote: Yes
Date Published: 2008-04-19
Relevant URL: http://www.securityfocus.com/bid/28858
Summary:
SubEdit Player is prone to a buffer-overflow vulnerability because it fai=
ls to perform adequate boundary checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

The issue affects SubEdit Player Build 4066; other versions may also be a=
ffected.

5. IBM DB2 Universal Database ADMIN_SP_C and ADMIN_SP_C2 Prodecures Remot=
e Code Execution Vulnerability
BugTraq ID: 28843
Remote: Yes
Date Published: 2008-04-18
Relevant URL: http://www.securityfocus.com/bid/28843
Summary:
IBM DB2 is prone to a remote code-execution vulnerability.

Attackers can exploit this issue to execute arbitrary code within the con=
text of the affected service. Successfully exploiting this issue may faci=
litate in the remote compromise of affected computers. Failed exploit att=
empts will likely crash the affected application.

6. IBM DB2 'NNSTAT' Procedure Arbitrary File Overwrite Vulnerability
BugTraq ID: 28836
Remote: No
Date Published: 2008-04-18
Relevant URL: http://www.securityfocus.com/bid/28836
Summary:
IBM DB2 is prone to a vulnerability that lets attackers overwrite arbitra=
ry files.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Successfully exploiting this issue wi=
ll compromise the application and possibly the underlying computer.

7. IBM DB2 Universal Database JAR File Processing Multiple Denial of Serv=
ice Vulnerabilities
BugTraq ID: 28835
Remote: Yes
Date Published: 2008-04-18
Relevant URL: http://www.securityfocus.com/bid/28835
Summary:
IBM DB2 Universal Database is prone to multiple denial-of-service vulnera=
bilities.

Successfully exploiting these issues allows authenticated attackers to ca=
use server crashes, denying service to legitimate users.

IBM DB2 Universal Database 8, 9, and 9.5 on Microsoft Windows platforms a=
re affected.

8. Microsoft Windows SeImpersonatePrivilege Local Privilege Escalation Vu=
lnerability
BugTraq ID: 28833
Remote: No
Date Published: 2008-04-17
Relevant URL: http://www.securityfocus.com/bid/28833
Summary:
Microsoft Windows is prone to a privilege-escalation vulnerability.

Successful exploits may allow authenticated users to elevate their privil=
eges to LocalSystem. This facilitates the complete compromise of affected=
 computers.

The issue affects Microsoft Windows XP Professional SP2 and all versions =
and editions of Windows Server 2003, Windows Vista, and Windows Server 20=
08.

9. ImageMagick Malformed PCX File Heap Overflow Vulnerability
BugTraq ID: 28822
Remote: Yes
Date Published: 2008-04-17
Relevant URL: http://www.securityfocus.com/bid/28822
Summary:
ImageMagick is prone to an heap-based buffer-overflow vulnerability becau=
se it fails to properly bounds-check user-supplied input. The vulnerabili=
ty occurs when handling malformed PCX files.

Successfully exploiting this issue allows attackers to execute arbitrary =
code with the privileges of a user running the application. Failed exploi=
t attempts will result in a denial-of-service condition.

ImageMagick 6.2.8-0 and 6.2.4-5 are vulnerable; other versions may also b=
e affected.

10. ImageMagick Malformed XCF File Heap Overflow Vulnerability
BugTraq ID: 28821
Remote: Yes
Date Published: 2008-04-17
Relevant URL: http://www.securityfocus.com/bid/28821
Summary:
ImageMagick is prone to a heap-based buffer-overflow vulnerability becaus=
e it fails to properly bounds-check user-supplied input. The vulnerabilit=
y occurs when handling malformed XCF files.

Successfully exploiting this issue allows attackers to execute arbitrary =
code with the privileges of a user running the application. Failed exploi=
t attempts will result in a denial-of-service condition.

ImageMagick 6.2.8-0 and earlier are vulnerable.

11. Microsoft Works 7 'WkImgSrv.dll' ActiveX Control Remote Code Executio=
n Vulnerability
BugTraq ID: 28820
Remote: Yes
Date Published: 2008-04-17
Relevant URL: http://www.securityfocus.com/bid/28820
Summary:
Microsoft Works 7 'WkImgSrv.dll' ActiveX control is prone to a remote cod=
e-execution vulnerability because it fails to sufficiently verify user-su=
pplied input.

An attacker can exploit this issue to run arbitrary attacker-supplied cod=
e in the context of the currently logged-in user. Failed exploits attempt=
s will trigger denial-of-service conditions.

This issue affects Microsoft Works 7 'WkImgSrv.dll' ActiveX control 7.03.=
0616; other versions may also be vulnerable.

12. Apple Safari WebKit JavaScript Regular Expression Repetition Counts B=
uffer Overflow Vulnerability
BugTraq ID: 28815
Remote: Yes
Date Published: 2008-04-16
Relevant URL: http://www.securityfocus.com/bid/28815
Summary:
Apple Safari is prone to a buffer-overflow vulnerability.=20

Attackers may exploit this issue to execute arbitrary code or to crash th=
e affected application. Other attacks are also possible.
=20
This issue affects versions prior to Apple Safari 3.1.1 running on the fo=
llowing platforms:

Mac OS X v10.4.11
Mac OS X Server v10.4.11
Mac OS X v10.5.2
Mac OS X Server v10.5.2
Windows XP
Windows Vista

13. Apple Safari WebKit URI Handling Cross-Site Scripting Vulnerability
BugTraq ID: 28814
Remote: Yes
Date Published: 2008-04-16
Relevant URL: http://www.securityfocus.com/bid/28814
Summary:
Apple Safari WebKit is prone to a cross-site scripting vulnerability beca=
use it fails to properly sanitize user-supplied input.

Attackers may leverage this issue to execute arbitrary script code in the=
 browser of an unsuspecting user in the context of the affected site. Thi=
s may allow attackers to steal cookie-based authentication credentials an=
d to launch other attacks.
=20
 This issue affects versions prior to Apple Safari 3.1.1 running on the f=
ollowing platforms:

Mac OS X 10.4.11=20
Mac OS X 10.5.2
Windows XP
Windows Vista.

14. Apple Safari File Download Remote Memory Corruption Vulnerability
BugTraq ID: 28813
Remote: Yes
Date Published: 2008-04-16
Relevant URL: http://www.securityfocus.com/bid/28813
Summary:
Apple Safari is prone to a remote memory-corruption vulnerability that oc=
curs when downloading malicious files.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

This issue affects versions prior to Apple Safari 3.1.1 running on Micros=
oft Windows XP and Windows Vista.

NOTE: This vulnerability may be related to the issue described in BID 284=
04 (Apple Safari File Download Remote Denial of Service Vulnerability).

15. ICQ 'Personal Status Manager' Remote Buffer Overflow Vulnerability
BugTraq ID: 28803
Remote: Yes
Date Published: 2008-04-16
Relevant URL: http://www.securityfocus.com/bid/28803
Summary:
ICQ is prone to a remote buffer-overflow vulnerability because the applic=
ation fails to perform boundary checks before copying user-supplied data =
into sensitive process buffers.

A remote attacker may execute arbitrary code in the context of the affect=
ed application. Failed exploit attempts will result in a denial of servic=
e.=20
=20
This issue affects ICQ 6 build 6043; other versions may also be vulnerabl=
e.

16. ClamAV 'libclamav/pe.c' WWPACK File Heap Based Buffer Overflow Vulner=
ability
BugTraq ID: 28798
Remote: Yes
Date Published: 2008-04-15
Relevant URL: http://www.securityfocus.com/bid/28798
Summary:
ClamAV is prone to a heap-based buffer-overflow vulnerability because it =
fails to properly verify user-supplied data.=20

Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the vu=
lnerable 'libclamav' library. Failed exploit attempts will likely cause d=
enial-of-service conditions.

ClamAV 0.92.1 is vulnerable to this issue; other versions may also be aff=
ected.

17. RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflo=
w Vulnerability
BugTraq ID: 28783
Remote: Yes
Date Published: 2008-04-15
Relevant URL: http://www.securityfocus.com/bid/28783
Summary:
ClamAV is prone to a heap-based buffer-overflow vulnerability because it =
fails to properly verify user-supplied data.=20

Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the vu=
lnerable 'libclamav' library. Failed exploit attempts will likely cause d=
enial-of-service conditions.

ClamAV 0.92 and 0.92.1 are vulnerable to this issue; other versions may a=
lso be affected.

NOTE: This BID is being retired because it is a duplicate of BID 28756.

18. Nero MediaHome NMMediaServer.EXE Remote Denial of Service Vulnerabili=
ty
BugTraq ID: 28775
Remote: Yes
Date Published: 2008-04-14
Relevant URL: http://www.securityfocus.com/bid/28775
Summary:
Nero MediaHome is prone to a remote denial-of-service vulnerability becau=
se the application fails to handle exceptional conditions.=20

An attacker can exploit this issue to crash the affected application, den=
ying further service to legitimate users.=20

This issue affects Nero MediaHome 3.3.3.0. Other versions may also be aff=
ected.

19. XM Easy Personal FTP Server 'PORT and 'XCWD' Multiple Remote Denial o=
f Service Vulnerabilities
BugTraq ID: 28759
Remote: Yes
Date Published: 2008-04-14
Relevant URL: http://www.securityfocus.com/bid/28759
Summary:
XM Easy Personal FTP Server is prone to multiple remote denial-of-service=
 vulnerabilities.

These issues allow remote attackers to crash affected FTP servers, denyin=
g service to legitimate users. Given the nature of these issues, attacker=
s may also be able to execute arbitrary code, but this has not been confi=
rmed.

XM Easy Personal FTP Server 5.4.0 is vulnerable; other versions may also =
be affected.

20. ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnera=
bility
BugTraq ID: 28756
Remote: Yes
Date Published: 2008-04-14
Relevant URL: http://www.securityfocus.com/bid/28756
Summary:
ClamAV is prone to a heap-based buffer-overflow vulnerability because it =
fails to properly verify user-supplied data.=20

Successful exploits of this vulnerability can allow remote attackers to e=
xecute arbitrary machine code in the context of applications using the vu=
lnerable 'libclamav' library. Failed exploit attempts will likely cause d=
enial-of-service conditions.

ClamAV 0.92 and 0.92.1 are vulnerable to this issue; other versions may a=
lso be affected.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #390
http://www.securityfocus.com/archive/88/490993

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by HP

Top 10 security vulnerabilities in .NET configuration files: are your web=
 applications vulnerable?
Even the smallest opening in your web application layer can grant full ac=
cess to an intruder. A hacker armed with nothing more than a web browser =
and knowledge of basic programming techniques can steal your most sensiti=
ve information by taking advantage of openings that exist in the the web =
server, application configuration and source code. This free white paper,=
 from HP Software, discusses the 10 most common .NET application configur=
ation mistakes, the devastating effects those mistakes can have as well a=
s best practices for managing configuration files to prevent attacks.
https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=3DdownloadPDF&zn=
=3Dbto&cp=3D54_4012_100__&caid=3D14532&jumpid=3Dex_r11374_us/en/large/tsg=
/Top10_Security_Vulnerabilities_WP_Newsletter/3-1A4COJW_3-ULBT8Q/20080429=
&origin_id=3D3-1A4COJW