SecurityFocus Microsoft Newsletter #395
[email protected] 21 May 2008 23:28:21 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #395
----------------------------------------
This issue is sponsored by Sphinx-Soft
VistaFirewallControl - controls Vista 32/64-bit applications outbound/inb=
ound activity by a single click.
Based on Vista security core; provides unbeatable stability and filtering=
quality of Microsoft; Synchronizes external uPnP hardware with applicati=
ons network permissions;
Download here http://sphinx-soft.com/Vista/order.html?SF
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Thinking Beyond the Ivory Towers
2.Click Crime
II. MICROSOFT VULNERABILITY SUMMARY
1. Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerabili=
ty
2. Computer Associates ARCserve Backup 'caloggerd' and 'xdr' Funct=
ions Multiple Remote Vulnerabilities
3. Symantec Altiris Deployment Solution Tooltip Local Privilege Es=
calation Vulnerability
4. Microsoft Internet Explorer 'Print Table of Links' Cross Zone S=
cript Injection Vulnerability
5. IDAutomation Barcode ActiveX Controls Multiple Arbitrary File O=
verwrite Vulnerabilities
6. Symantec Altiris Deployment Solution Domain Credential Unauthor=
ized Access Vulnerability
7. Symantec Altiris Deployment Solution 'axengine.exe' SQL Injecti=
on Vulnerability
8. Symantec Altiris Deployment Solution Install Directory Local Pr=
ivilege Escalation Vulnerability
9. Symantec Altiris Deployment Solution Registry Keys Local Unauth=
orized Access Vulnerability
10. Symantec Altiris Deployment Solution Agent User Interface Loca=
l Privilege Escalation Vulnerability
11. Multiple Platform IPv6 Address Publication Denial of Service V=
ulnerabilities
12. Jenkins Software RakNet Autopatcher Multiple Unspecified SQL I=
njection Vulnerabilities
13. Microsoft Windows Intelligent Input/Output (I2O) Multiple Loca=
l Privilege Escalation Vulnerabilities
14. Microsoft Publisher Memory Object Handler Data Remote Code Exe=
cution Vulnerability
15. Microsoft Word CSS Handling Memory Corruption Remote Code Exec=
ution Vulnerability
16. Microsoft Word RTF Malformed String Handling Memory Corruption=
Remote Code Execution Vulnerability
17. Microsoft Malware Protection Engine Disk Space Exhaustion Remo=
te Denial Of Service Vulnerability
18. Microsoft Malware Protection Engine File Processing Remote Den=
ial Of Service Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. Binding Windows Services to Specific Addresses Only
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Thinking Beyond the Ivory Towers
By Dave Aitel
In the information-security industry, there are clear and vast gaps in th=
e way academia interacts with professional researchers. While these gaps =
will be filled in due time, their existence means that security professio=
nals outside the hallowed halls of colleges and universities need to be a=
ware of the differences in how researchers and professionals think.=20
http://www.securityfocus.com/columnists/472
2. Click Crime
By Mark Rasch
It has long been a crime not only to commit an illegal act, but also to a=
ttempt -- or conspire with others -- to commit one.=20
http://www.securityfocus.com/columnists/471
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
BugTraq ID: 29288
Remote: Yes
Date Published: 2008-05-20
Relevant URL: http://www.securityfocus.com/bid/29288
Summary:
Foxit Reader is prone to a remote buffer-overflow vulnerability when hand=
ling PDF files with specially crafted JavaScript code.
Exploiting this issue may allow attackers to corrupt memory and execute a=
rbitrary machine code in the context of users running the affected applic=
ation. Failed exploit will likely cause denial-of-service conditions.
=20
This issue affects Foxit Reader 2.3 build 2825; other versions may also b=
e affected.
2. Computer Associates ARCserve Backup 'caloggerd' and 'xdr' Functions Mu=
ltiple Remote Vulnerabilities
BugTraq ID: 29283
Remote: Yes
Date Published: 2008-05-19
Relevant URL: http://www.securityfocus.com/bid/29283
Summary:
Computer Associates ARCserve Backup is prone to multiple remote vulnerabi=
lities:=20
- An arbitrary-file-overwrite vulnerability
- A stack-based buffer-overflow vulnerability.=20
An attacker can exploit these issues to execute arbitrary code with SYSTE=
M-level privileges. Successfully exploiting these issues will result in t=
he complete compromise of affected computers. Failed exploit attempts wil=
l result in a denial-of-service condition.
3. Symantec Altiris Deployment Solution Tooltip Local Privilege Escalatio=
n Vulnerability
BugTraq ID: 29218
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29218
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.
An attacker can exploit this issue to gain access to a privileged command=
prompt. Successfully exploiting this issue will result in the complete c=
ompromise of affected computers.
4. Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script I=
njection Vulnerability
BugTraq ID: 29217
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29217
Summary:
Microsoft Internet Explorer is prone to a script-injection vulnerability =
because it fails to adequately sanitize user-supplied input when printing=
a table of links.
Attackers can exploit this issue by enticing an unsuspecting user to init=
iate the printing procedure while viewing a specially crafted page. Succe=
ssful exploits will cause malicious script code to run in the 'Local Mach=
ine Zone' of a victim's computer.
Internet Explorer 7.0 and 8.0b are vulnerable; other versions may also be=
affected.
Reports indicate that successful exploits on Windows Vista platforms runn=
ing UAC can cause only information disclosure.
5. IDAutomation Barcode ActiveX Controls Multiple Arbitrary File Overwrit=
e Vulnerabilities
BugTraq ID: 29204
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29204
Summary:
IDAutomation Barcode ActiveX controls are prone to multiple vulnerabiliti=
es that allow attackers to overwrite arbitrary files.=20
An attacker can exploit these issues by enticing an unsuspecting victim t=
o view a malicious HTML page.=20
Successfully exploiting these issues will allow the attacker to corrupt a=
nd overwrite arbitrary files on the victim's computer in the context of t=
he vulnerable application using the ActiveX control (typically Internet E=
xplorer).
The following applications are vulnerable:
Linear Barcode ActiveX Control 1.6.0.6
Data Matrix Barcode Font & Encoder 1.6.0.6
PDF417 Barcode Font and Encoder 1.6.0.6
Aztec Barcode Font & Encoder 1.7.1.0
Other versions may also be affected.
6. Symantec Altiris Deployment Solution Domain Credential Unauthorized Ac=
cess Vulnerability
BugTraq ID: 29199
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29199
Summary:
Symantec Altiris Deployment Solution is prone to a vulnerability that all=
ows an attacker to gain unauthorized access to the affected application.=20
The attacker can exploit this issue to gain administrative access to the =
application. Successfully exploiting this issue will compromise the affec=
ted application.
7. Symantec Altiris Deployment Solution 'axengine.exe' SQL Injection Vuln=
erability
BugTraq ID: 29198
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29198
Summary:
Symantec Altiris Deployment Solution is prone to an SQL-injection vulnera=
bility because it fails to sufficiently sanitize user-supplied data befor=
e using it in an SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code w=
ith SYSTEM-level privileges. Successfully exploiting this issue will faci=
litate in the complete compromise of affected computers.
Versions prior to Symantec Altiris Deployment Solution 6.9.176 are vulner=
able.
8. Symantec Altiris Deployment Solution Install Directory Local Privilege=
Escalation Vulnerability
BugTraq ID: 29197
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29197
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.
An attacker can exploit this issue to execute arbitrary commands with SYS=
TEM-level privileges. Successfully exploiting this issue will result in t=
he complete compromise of affected computers.
9. Symantec Altiris Deployment Solution Registry Keys Local Unauthorized =
Access Vulnerability
BugTraq ID: 29196
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29196
Summary:
Symantec Altiris Deployment Solution is prone to a local unauthorized-acc=
ess vulnerability.
=20
An attacker with local access to the computer may be able to access cert=
ain registry keys. A successful attack may allow the attacker to obtain i=
nformation or to disrupt service.
10. Symantec Altiris Deployment Solution Agent User Interface Local Privi=
lege Escalation Vulnerability
BugTraq ID: 29194
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29194
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.
An attacker can exploit this issue to gain access to a privileged command=
prompt. Successfully exploiting this issue will result in the complete c=
ompromise of affected computers.
11. Multiple Platform IPv6 Address Publication Denial of Service Vulnerab=
ilities
BugTraq ID: 29190
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29190
Summary:
Multiple operating systems are prone to remote denial-of-service vulnerab=
ilities that occur when affected operating systems are acting as IPv6 rou=
ters.
Successful exploits allow remote attackers to cause computers to consume =
excessive CPU resources or to stop responding to advertised routes in a n=
etwork. This will potentially deny further network services to legitimate=
users.
Microsoft Windows XP, Microsoft Windows Server 2003, and Linux are prone=
to these issues. Other operating systems may also be affected.
12. Jenkins Software RakNet Autopatcher Multiple Unspecified SQL Injectio=
n Vulnerabilities
BugTraq ID: 29178
Remote: Yes
Date Published: 2008-05-12
Relevant URL: http://www.securityfocus.com/bid/29178
Summary:
RakNet Autopatcher is prone to multiple SQL-injection vulnerabilities bec=
ause it fails to sufficiently sanitize user-supplied data before using it=
in SQL queries.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
Versions prior to RakNet 3.23 are vulnerable.
13. Microsoft Windows Intelligent Input/Output (I2O) Multiple Local Privi=
lege Escalation Vulnerabilities
BugTraq ID: 29171
Remote: No
Date Published: 2008-05-12
Relevant URL: http://www.securityfocus.com/bid/29171
Summary:
Microsoft Windows is prone to multiple local privilege-escalation vulnera=
bilities. =20
An attacker can exploit these issues to execute arbitrary code with kerne=
l-level privileges. Successfully exploiting these issues will completely =
compromise affected computers.
These issues affect Windows XP prior to SP3.
14. Microsoft Publisher Memory Object Handler Data Remote Code Execution =
Vulnerability
BugTraq ID: 29158
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29158
Summary:
Microsoft Publisher is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malic=
ious Publisher file.=20
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
15. Microsoft Word CSS Handling Memory Corruption Remote Code Execution V=
ulnerability
BugTraq ID: 29105
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29105
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malic=
ious Word file.=20
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
16. Microsoft Word RTF Malformed String Handling Memory Corruption Remote=
Code Execution Vulnerability
BugTraq ID: 29104
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29104
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
17. Microsoft Malware Protection Engine Disk Space Exhaustion Remote Deni=
al Of Service Vulnerability
BugTraq ID: 29073
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29073
Summary:
Microsoft Malware Protection Engine is prone to a remote denial-of-servic=
e vulnerability because it fails to properly validate certain data struct=
ures when parsing specially crafted files.
Attackers can exploit this issue to cause an affected computer to stop re=
sponding or to restart. Successful attacks will deny service to legitimat=
e users.
18. Microsoft Malware Protection Engine File Processing Remote Denial Of =
Service Vulnerability
BugTraq ID: 29060
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29060
Summary:
Microsoft Malware Protection Engine is prone to a remote denial-of-servic=
e vulnerability because it fails to properly validate user-supplied input=
when parsing specially crafted files.
Attackers can exploit this issue to cause an affected computer to stop re=
sponding or to restart. Successful attacks will deny service to legitimat=
e users.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Binding Windows Services to Specific Addresses Only
http://www.securityfocus.com/archive/88/491595
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Sphinx-Soft
VistaFirewallControl - controls Vista 32/64-bit applications outbound/inb=
ound activity by a single click.
Based on Vista security core; provides unbeatable stability and filtering=
quality of Microsoft; Synchronizes external uPnP hardware with applicati=
ons network permissions;
Download here http://sphinx-soft.com/Vista/order.html?SF