SecurityFocus Microsoft Newsletter #395

[email protected] 21 May 2008 23:28:21 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #395
----------------------------------------

This issue is sponsored by Sphinx-Soft

VistaFirewallControl - controls Vista 32/64-bit applications outbound/inb=
ound activity by a single click.
Based on Vista security core; provides unbeatable stability and filtering=
 quality of Microsoft; Synchronizes external uPnP hardware with applicati=
ons network permissions;
Download here http://sphinx-soft.com/Vista/order.html?SF


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.Thinking Beyond the Ivory Towers
       2.Click Crime
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerabili=
ty
       2. Computer Associates ARCserve Backup 'caloggerd' and 'xdr' Funct=
ions Multiple Remote Vulnerabilities
       3. Symantec Altiris Deployment Solution Tooltip Local Privilege Es=
calation Vulnerability
       4. Microsoft Internet Explorer 'Print Table of Links' Cross Zone S=
cript Injection Vulnerability
       5. IDAutomation Barcode ActiveX Controls Multiple Arbitrary File O=
verwrite Vulnerabilities
       6. Symantec Altiris Deployment Solution Domain Credential Unauthor=
ized Access Vulnerability
       7. Symantec Altiris Deployment Solution 'axengine.exe' SQL Injecti=
on Vulnerability
       8. Symantec Altiris Deployment Solution Install Directory Local Pr=
ivilege Escalation Vulnerability
       9. Symantec Altiris Deployment Solution Registry Keys Local Unauth=
orized Access Vulnerability
       10. Symantec Altiris Deployment Solution Agent User Interface Loca=
l Privilege Escalation Vulnerability
       11. Multiple Platform IPv6 Address Publication Denial of Service V=
ulnerabilities
       12. Jenkins Software RakNet Autopatcher Multiple Unspecified SQL I=
njection Vulnerabilities
       13. Microsoft Windows Intelligent Input/Output (I2O) Multiple Loca=
l Privilege Escalation Vulnerabilities
       14. Microsoft Publisher Memory Object Handler Data Remote Code Exe=
cution Vulnerability
       15. Microsoft Word CSS Handling Memory Corruption Remote Code Exec=
ution Vulnerability
       16. Microsoft Word RTF Malformed String Handling Memory Corruption=
 Remote Code Execution Vulnerability
       17. Microsoft Malware Protection Engine Disk Space Exhaustion Remo=
te Denial Of Service Vulnerability
       18. Microsoft Malware Protection Engine File Processing Remote Den=
ial Of Service Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. Binding Windows Services to Specific Addresses Only
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Thinking Beyond the Ivory Towers
By Dave Aitel
In the information-security industry, there are clear and vast gaps in th=
e way academia interacts with professional researchers. While these gaps =
will be filled in due time, their existence means that security professio=
nals outside the hallowed halls of colleges and universities need to be a=
ware of the differences in how researchers and professionals think.=20
http://www.securityfocus.com/columnists/472

2. Click Crime
By Mark Rasch
It has long been a crime not only to commit an illegal act, but also to a=
ttempt -- or conspire with others -- to commit one.=20
http://www.securityfocus.com/columnists/471


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Foxit Reader 'util.printf()' Remote Buffer Overflow Vulnerability
BugTraq ID: 29288
Remote: Yes
Date Published: 2008-05-20
Relevant URL: http://www.securityfocus.com/bid/29288
Summary:
Foxit Reader is prone to a remote buffer-overflow vulnerability when hand=
ling PDF files with specially crafted JavaScript code.

Exploiting this issue may allow attackers to corrupt memory and execute a=
rbitrary machine code in the context of users running the affected applic=
ation. Failed exploit will likely cause denial-of-service conditions.
=20
This issue affects Foxit Reader 2.3 build 2825; other versions may also b=
e affected.

2. Computer Associates ARCserve Backup 'caloggerd' and 'xdr' Functions Mu=
ltiple Remote Vulnerabilities
BugTraq ID: 29283
Remote: Yes
Date Published: 2008-05-19
Relevant URL: http://www.securityfocus.com/bid/29283
Summary:
Computer Associates ARCserve Backup is prone to multiple remote vulnerabi=
lities:=20

- An arbitrary-file-overwrite vulnerability
- A stack-based buffer-overflow vulnerability.=20

An attacker can exploit these issues to execute arbitrary code with SYSTE=
M-level privileges. Successfully exploiting these issues will result in t=
he complete compromise of affected computers. Failed exploit attempts wil=
l result in a denial-of-service condition.

3. Symantec Altiris Deployment Solution Tooltip Local Privilege Escalatio=
n Vulnerability
BugTraq ID: 29218
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29218
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.

An attacker can exploit this issue to gain access to a privileged command=
 prompt. Successfully exploiting this issue will result in the complete c=
ompromise of affected computers.

4. Microsoft Internet Explorer 'Print Table of Links' Cross Zone Script I=
njection Vulnerability
BugTraq ID: 29217
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29217
Summary:
Microsoft Internet Explorer is prone to a script-injection vulnerability =
because it fails to adequately sanitize user-supplied input when printing=
 a table of links.

Attackers can exploit this issue by enticing an unsuspecting user to init=
iate the printing procedure while viewing a specially crafted page. Succe=
ssful exploits will cause malicious script code to run in the 'Local Mach=
ine Zone' of a victim's computer.

Internet Explorer 7.0 and 8.0b are vulnerable; other versions may also be=
 affected.

Reports indicate that successful exploits on Windows Vista platforms runn=
ing UAC can cause only information disclosure.

5. IDAutomation Barcode ActiveX Controls Multiple Arbitrary File Overwrit=
e Vulnerabilities
BugTraq ID: 29204
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29204
Summary:
IDAutomation Barcode ActiveX controls are prone to multiple vulnerabiliti=
es that allow attackers to overwrite arbitrary files.=20

An attacker can exploit these issues by enticing an unsuspecting victim t=
o view a malicious HTML page.=20

Successfully exploiting these issues will allow the attacker to corrupt a=
nd overwrite arbitrary files on the victim's computer in the context of t=
he vulnerable application using the ActiveX control (typically Internet E=
xplorer).

The following applications are vulnerable:

Linear Barcode ActiveX Control 1.6.0.6
Data Matrix Barcode Font &amp; Encoder 1.6.0.6
PDF417 Barcode Font and Encoder 1.6.0.6
Aztec Barcode Font &amp; Encoder 1.7.1.0

Other versions may also be affected.

6. Symantec Altiris Deployment Solution Domain Credential Unauthorized Ac=
cess Vulnerability
BugTraq ID: 29199
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29199
Summary:
Symantec Altiris Deployment Solution is prone to a vulnerability that all=
ows an attacker to gain unauthorized access to the affected application.=20

The attacker can exploit this issue to gain administrative access to the =
application. Successfully exploiting this issue will compromise the affec=
ted application.

7. Symantec Altiris Deployment Solution 'axengine.exe' SQL Injection Vuln=
erability
BugTraq ID: 29198
Remote: Yes
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29198
Summary:
Symantec Altiris Deployment Solution is prone to an SQL-injection vulnera=
bility because it fails to sufficiently sanitize user-supplied data befor=
e using it in an SQL query.

Exploiting this issue could allow an attacker to execute arbitrary code w=
ith SYSTEM-level privileges. Successfully exploiting this issue will faci=
litate in the complete compromise of affected computers.

Versions prior to Symantec Altiris Deployment Solution 6.9.176 are vulner=
able.

8. Symantec Altiris Deployment Solution Install Directory Local Privilege=
 Escalation Vulnerability
BugTraq ID: 29197
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29197
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.

An attacker can exploit this issue to execute arbitrary commands with SYS=
TEM-level privileges. Successfully exploiting this issue will result in t=
he complete compromise of affected computers.

9. Symantec Altiris Deployment Solution Registry Keys Local Unauthorized =
Access Vulnerability
BugTraq ID: 29196
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29196
Summary:
Symantec Altiris Deployment Solution is prone to a local unauthorized-acc=
ess vulnerability.
=20
 An attacker with local access to the computer may be able to access cert=
ain registry keys. A successful attack may allow the attacker to obtain i=
nformation or to disrupt service.

10. Symantec Altiris Deployment Solution Agent User Interface Local Privi=
lege Escalation Vulnerability
BugTraq ID: 29194
Remote: No
Date Published: 2008-05-14
Relevant URL: http://www.securityfocus.com/bid/29194
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.

An attacker can exploit this issue to gain access to a privileged command=
 prompt. Successfully exploiting this issue will result in the complete c=
ompromise of affected computers.

11. Multiple Platform IPv6 Address Publication Denial of Service Vulnerab=
ilities
BugTraq ID: 29190
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29190
Summary:
Multiple operating systems are prone to remote denial-of-service vulnerab=
ilities that occur when affected operating systems are acting as IPv6 rou=
ters.

Successful exploits allow remote attackers to cause computers to consume =
excessive CPU resources or to stop responding to advertised routes in a n=
etwork. This will potentially deny further network services to legitimate=
 users.

 Microsoft Windows XP, Microsoft Windows Server 2003, and Linux are prone=
 to these issues. Other operating systems may also be affected.

12. Jenkins Software RakNet Autopatcher Multiple Unspecified SQL Injectio=
n Vulnerabilities
BugTraq ID: 29178
Remote: Yes
Date Published: 2008-05-12
Relevant URL: http://www.securityfocus.com/bid/29178
Summary:
RakNet Autopatcher is prone to multiple SQL-injection vulnerabilities bec=
ause it fails to sufficiently sanitize user-supplied data before using it=
 in SQL queries.

Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.

Versions prior to RakNet 3.23 are vulnerable.

13. Microsoft Windows Intelligent Input/Output (I2O) Multiple Local Privi=
lege Escalation Vulnerabilities
BugTraq ID: 29171
Remote: No
Date Published: 2008-05-12
Relevant URL: http://www.securityfocus.com/bid/29171
Summary:
Microsoft Windows is prone to multiple local privilege-escalation vulnera=
bilities. =20

An attacker can exploit these issues to execute arbitrary code with kerne=
l-level privileges. Successfully exploiting these issues will completely =
compromise affected computers.

These issues affect Windows XP prior to SP3.

14. Microsoft Publisher Memory Object Handler Data Remote Code Execution =
Vulnerability
BugTraq ID: 29158
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29158
Summary:
Microsoft Publisher is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious Publisher file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

15. Microsoft Word CSS Handling Memory Corruption Remote Code Execution V=
ulnerability
BugTraq ID: 29105
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29105
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious Word file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

16. Microsoft Word RTF Malformed String Handling Memory Corruption Remote=
 Code Execution Vulnerability
BugTraq ID: 29104
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29104
Summary:
Microsoft Word is prone to a remote code-execution vulnerability.

An attacker could exploit this issue by enticing a victim to open a malic=
ious RTF file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

17. Microsoft Malware Protection Engine Disk Space Exhaustion Remote Deni=
al Of Service Vulnerability
BugTraq ID: 29073
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29073
Summary:
Microsoft Malware Protection Engine is prone to a remote denial-of-servic=
e vulnerability because it fails to properly validate certain data struct=
ures when parsing specially crafted files.

Attackers can exploit this issue to cause an affected computer to stop re=
sponding or to restart. Successful attacks will deny service to legitimat=
e users.

18. Microsoft Malware Protection Engine File Processing Remote Denial Of =
Service Vulnerability
BugTraq ID: 29060
Remote: Yes
Date Published: 2008-05-13
Relevant URL: http://www.securityfocus.com/bid/29060
Summary:
Microsoft Malware Protection Engine is prone to a remote denial-of-servic=
e vulnerability because it fails to properly validate user-supplied input=
 when parsing specially crafted files.

Attackers can exploit this issue to cause an affected computer to stop re=
sponding or to restart. Successful attacks will deny service to legitimat=
e users.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Binding Windows Services to Specific Addresses Only
http://www.securityfocus.com/archive/88/491595

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Sphinx-Soft

VistaFirewallControl - controls Vista 32/64-bit applications outbound/inb=
ound activity by a single click.
Based on Vista security core; provides unbeatable stability and filtering=
 quality of Microsoft; Synchronizes external uPnP hardware with applicati=
ons network permissions;
Download here http://sphinx-soft.com/Vista/order.html?SF