SecurityFocus Microsoft Newsletter #399
[email protected] 20 Jun 2008 17:16:21 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #399
----------------------------------------
This issue is sponsored by Black Hat USA:
Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts. Featuring 40 hands-on training course=
s and 80 Briefings presentations with lots of new content and new tools. =
Network with 4,000 delegates from 50 nations. Visit product displays by=
30 top sponsors in a relaxed setting.=20
www.blackhat.com
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Racing Against Reversers
2.Anti-Social Networking
II. MICROSOFT VULNERABILITY SUMMARY
1. Apple Safari Automatic File Launch Remote Code Execution Vulner=
ability
2. Microsoft Visual Basic Enterprise Edition 6 'vb6skit.dll' Remot=
e Buffer Overflow Vulnerability
3. UltraEdit FTP/SFTP 'LIST' Command Directory Traversal Vulnerabi=
lity
4. Microsoft Word Bulleted List Handling Remote Memory Corruption =
Vulnerability
5. Skulltag Malformed Packet Denial of Service Vulnerability
6. No-IP DUC Client for Windows Local Information Disclosure Vulne=
rability
7. 3D-FTP 'LIST' and 'MLSD' Directory Traversal Vulnerabilities
8. Glub Tech Secure FTP 'LIST' Command Directory Traversal Vulnera=
bility
9. artegic AG Dana Remote Buffer Overflow Vulnerability
10. muvee autoProducer 'TextOut.dll' ActiveX Control Remote Buffer=
Overflow Vulnerability
11. RETIRED: Apple QuickTime Multiple Arbitrary Code Execution Vul=
nerabilities
12. Microsoft Windows WINS Server Local Privilege Escalation Vulne=
rability
13. Microsoft Windows Active Directory LDAP Request Validation Rem=
ote Denial Of Service Vulnerability
14. Microsoft DirectX MJPEG Video Streaming Stack Based Buffer Ove=
rflow Vulnerability
15. Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflo=
w Vulnerability
16. Microsoft Internet Explorer HTML Objects 'substringData()' Rem=
ote Code Execution Vulnerability
17. Microsoft Windows Bluetooth Stack Remote Code Execution Vulner=
ability
18. Microsoft Windows PGM Invalid Fragment Remote Denial Of Servic=
e Vulnerability
19. Microsoft Windows PGM Invalid Length Remote Denial Of Service =
Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. default for requiring authentication 2003
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Racing Against Reversers
By Federico Biancuzzi
Each time a new digital rights management (DRM) system is released, hacke=
rs are not far behind in cracking it. Reverse engineers have taken down t=
he security protecting content encoded for Windows Media, iTunes, DVDs, a=
nd HD-DVDs.=20
http://www.securityfocus.com/columnists/474
2.Anti-Social Networking
By Mark Rasch
On May 15, 2008, a federal grand jury Los Angeles indicted 49-year-old Lo=
ri Drew of O.Fallon, Missouri, on charges of unauthorized access to a com=
puter, typically used in hacking cases. Yet, Drew's alleged actions had l=
ittle to do with computer intrusions.=20
http://www.securityfocus.com/columnists/473
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Apple Safari Automatic File Launch Remote Code Execution Vulnerability
BugTraq ID: 29835
Remote: Yes
Date Published: 2008-06-19
Relevant URL: http://www.securityfocus.com/bid/29835
Summary:
Apple Safari is prone to a remote code-execution vulnerability.=20
An attacker can exploit this issue by enticing an unsuspecting victim to =
visit a malicious webpage contained in a trusted Internet Explorer 7 zone=
or contained in an Internet Explorer 6 'local intranet' or 'Trusted site=
' zone.
=20
Successfully exploiting this issue will allow attackers to execute arbitr=
ary code with the privileges of the user running the affected application=
.=20
This issue affects versions prior to Apple Safari 3.1.2 running on Micros=
oft Windows XP and Windows Vista.
2. Microsoft Visual Basic Enterprise Edition 6 'vb6skit.dll' Remote Buffe=
r Overflow Vulnerability
BugTraq ID: 29792
Remote: Yes
Date Published: 2008-06-18
Relevant URL: http://www.securityfocus.com/bid/29792
Summary:
Microsoft Visual Basic Enterprise Edition 6 is prone to a stack-based buf=
fer-overflow vulnerability because it fails to perform adequate size chec=
ks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the vulnerable application. Failed exploit at=
tempts will result in a denial-of-service condition.
Microsoft Visual Basic Enterprise Edition 6 SP6 is vulnerable; other vers=
ions may also be affected.
3. UltraEdit FTP/SFTP 'LIST' Command Directory Traversal Vulnerability
BugTraq ID: 29784
Remote: Yes
Date Published: 2008-06-17
Relevant URL: http://www.securityfocus.com/bid/29784
Summary:
UltraEdit is prone to a directory-traversal vulnerability because the app=
lication fails to sufficiently sanitize user-supplied input. This issue o=
ccurs in the FTP/SFTP client.
Exploiting this issue will allow an attacker to write arbitrary files to =
locations outside of the application's current directory. This could help=
the attacker launch further attacks.
UltraEdit 14.00b is vulnerable; other versions may also be affected.
4. Microsoft Word Bulleted List Handling Remote Memory Corruption Vulnera=
bility
BugTraq ID: 29769
Remote: Yes
Date Published: 2008-06-17
Relevant URL: http://www.securityfocus.com/bid/29769
Summary:
Microsoft Word is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue by enticing a victim to open and int=
eract with malicious Word files.
Successfully exploiting this issue will corrupt memory and crash the appl=
ication. Given the nature of this issue, attackers may also be able to ex=
ecute arbitrary code in the context of the currently logged-in user.
5. Skulltag Malformed Packet Denial of Service Vulnerability
BugTraq ID: 29760
Remote: Yes
Date Published: 2008-06-16
Relevant URL: http://www.securityfocus.com/bid/29760
Summary:
Skulltag is prone to a vulnerability that can cause denial-of-service con=
ditions.
A successful attack will deny service to legitimate users.
Skulltag 0.97d2-RC3 is vulnerable; other versions may also be affected.
6. No-IP DUC Client for Windows Local Information Disclosure Vulnerabilit=
y
BugTraq ID: 29758
Remote: No
Date Published: 2008-06-16
Relevant URL: http://www.securityfocus.com/bid/29758
Summary:
The DUC application for No-IP is prone to a local information-disclosure =
vulnerability when it is running on Microsoft Windows.
Successfully exploiting this issue allows attackers to obtain potentially=
sensitive information that may aid in further attacks.
7. 3D-FTP 'LIST' and 'MLSD' Directory Traversal Vulnerabilities
BugTraq ID: 29749
Remote: Yes
Date Published: 2008-06-16
Relevant URL: http://www.securityfocus.com/bid/29749
Summary:
3D-FTP is prone to multiple directory-traversal vulnerabilities because i=
t fails to sufficiently sanitize user-supplied input data.
Exploiting these issues allows an attacker to write arbitrary files to lo=
cations outside of the FTP client's current directory. This could help th=
e attacker launch further attacks.
3D-FTP 8.01 is vulnerable; other versions may also be affected.
8. Glub Tech Secure FTP 'LIST' Command Directory Traversal Vulnerability
BugTraq ID: 29741
Remote: Yes
Date Published: 2008-06-13
Relevant URL: http://www.securityfocus.com/bid/29741
Summary:
Glub Tech Secure FTP is prone to a directory-traversal vulnerability beca=
use the application fails to sufficiently sanitize user-supplied input. T=
his issue occurs in the FTP client.
Exploiting these issues will allow an attacker to write arbitrary files t=
o locations outside of the application's current directory. This could he=
lp the attacker launch further attacks.=20
Secure FTP 2.5.15 for Microsoft Windows is vulnerable; other versions may=
also be affected.
9. artegic AG Dana Remote Buffer Overflow Vulnerability
BugTraq ID: 29724
Remote: Yes
Date Published: 2008-06-14
Relevant URL: http://www.securityfocus.com/bid/29724
Summary:
Dana is prone to a remote buffer-overflow vulnerability because the appli=
cation fails to properly bounds-check user-supplied input before copying =
it to an insufficiently sized memory buffer.
An attacker may exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service. =20
This issue affects Dana 1.3 and prior versions.
10. muvee autoProducer 'TextOut.dll' ActiveX Control Remote Buffer Overfl=
ow Vulnerability
BugTraq ID: 29693
Remote: Yes
Date Published: 2008-06-12
Relevant URL: http://www.securityfocus.com/bid/29693
Summary:
The 'muvee autoProducer' program is prone to a stack-based buffer-overflo=
w vulnerability because it fails to perform adequate boundary checks on u=
ser-supplied input.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of an application using the affected ActiveX control (typically Intern=
et Explorer). Failed attacks will likely cause denial-of-service conditio=
ns.
This issue affects muvee autoProducer 6.1; other versions may also be aff=
ected.
11. RETIRED: Apple QuickTime Multiple Arbitrary Code Execution Vulnerabil=
ities
BugTraq ID: 29619
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29619
Summary:
Apple QuickTime is prone to multiple remote vulnerabilities that may allo=
w remote attackers to execute arbitrary code.
These issues arise when the application handles specially crafted PICT im=
age files, Indeo video content, movie files, 'file:' URIs, and AAC-encode=
d media. Successful exploits may allow attackers to gain remote unauthori=
zed access in the context of a vulnerable user; failed exploits will caus=
e denial-of-service conditions.
Versions prior to QuickTime 7.5 are affected.
NOTE: This BID is being retired; the following individual records have be=
en created to better document the issues:
29649 Apple QuickTime 'PICT' Image 'PixData' Structures Handling Heap Ove=
rflow Vulnerability
29650 Apple QuickTime 'file:' URI File Execution Vulnerability
29654 Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
29648 Apple QuickTime 'PICT' Image Buffer Overflow Vulnerability
29652 Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
12. Microsoft Windows WINS Server Local Privilege Escalation Vulnerabilit=
y
BugTraq ID: 29588
Remote: No
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29588
Summary:
Microsoft Windows WINS server is prone to a local privilege-escalation vu=
lnerability that may be triggered by malicious WINS network packets.
Successful exploits allow local attackers to execute arbitrary code with =
SYSTEM-level privileges, completely compromising the affected computer.
13. Microsoft Windows Active Directory LDAP Request Validation Remote Den=
ial Of Service Vulnerability
BugTraq ID: 29584
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29584
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause Microsoft Active Directory, ADAM (Active Directory Application Mode=
), and AD LDS (Active Directory Lightweight Directory Service) fail to ha=
ndle specially crafted Lightweight Directory Access Protocol (LDAP) reque=
sts.=20
=20
An attacker can exploit this issue by sending a specially crafted LDAP re=
quest to the affected computer. This would cause the affected system to t=
emporarily stop responding to LDAP requests, thus denying further service=
to legitimate users.
Note that the attacker requires valid logon credentials to exploit this i=
ssue on Windows Server 2003 and on any system that has ADAM installed.
This issue affects these components:
- Active Directory on Microsoft Windows 2000, Windows Server 2003, and Wi=
ndows Server 2008
- ADAM on Windows XP Professional and Windows Server 2003
- AD LDS on Windows Server 2008
Supported editions of Windows Server 2008 are not affected if installed u=
sing the Server Core installation option.
14. Microsoft DirectX MJPEG Video Streaming Stack Based Buffer Overflow V=
ulnerability
BugTraq ID: 29581
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29581
Summary:
Microsoft DirectX is prone to a stack-based buffer-overflow vulnerability=
because the application fails to perform adequate boundary checks on use=
r-supplied data.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application that uses =
DirectX. Failed exploit attempts will result in a denial-of-service condi=
tion.
NOTE: Supported editions of Windows Server 2008 are not affected if insta=
lled using the Server Core installation option.
15. Microsoft DirectX SAMI File Parsing Stack Based Buffer Overflow Vulne=
rability
BugTraq ID: 29578
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29578
Summary:
Microsoft DirectX is prone to a stack-based buffer-overflow vulnerability=
because it fails to perform adequate boundary checks on user-supplied da=
ta. The vulnerability occurs when handling malformed SAMI files.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application that uses =
DirectX. Failed exploit attempts will result in a denial-of-service condi=
tion.
NOTE: Supported editions of Windows Server 2008 are not affected if insta=
lled using the Server Core installation option.
16. Microsoft Internet Explorer HTML Objects 'substringData()' Remote Cod=
e Execution Vulnerability
BugTraq ID: 29556
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29556
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity because it fails to perform adequate boundary checks when handling c=
ertain HTML object data.
Attackers can leverage this issue to execute arbitrary code with the priv=
ileges of the user running the application. Successful exploits will comp=
romise affected computers. Failed attacks may cause denial-of-service con=
ditions.
17. Microsoft Windows Bluetooth Stack Remote Code Execution Vulnerability
BugTraq ID: 29522
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29522
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability becau=
se its implementation of the Bluetooth stack fails to adequately handle a=
flood of specially crafted SDP (Service Discovery Protocol) requests.
=20
To exploit this issue, an attacker must be within close physical proximit=
y of the affected computer.
Attackers can exploit this issue to execute arbitrary code with SYSTEM-le=
vel privileges. Successful exploits will completely compromise affected c=
omputers.
This issue affects only computers with Bluetooth capability.
18. Microsoft Windows PGM Invalid Fragment Remote Denial Of Service Vulne=
rability
BugTraq ID: 29509
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29509
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause it fails to adequately handle specially crafted PGM (Pragmatic Gene=
ral Multicast) network traffic.
Attackers can exploit this issue to cause affected computers to stop resp=
onding until all the malformed packets have been processed. Successful at=
tacks will deny service to legitimate users.=20
On computers running Windows XP and Windows Server 2003, PGM is enabled o=
nly when Microsoft Message Queuing (MSMQ) 3.0 is installed. The MSMQ serv=
ice is not installed by default.
On computers running Windows Vista or Windows Server 2008, PGM is enabled=
only when Microsoft Message Queuing (MSMQ) 4.0 is installed and when PGM=
is specifically enabled. The MSMQ service is not installed by default. =
When MSMQ is installed, PGM processing is not enabled by default.
19. Microsoft Windows PGM Invalid Length Remote Denial Of Service Vulnera=
bility
BugTraq ID: 29508
Remote: Yes
Date Published: 2008-06-10
Relevant URL: http://www.securityfocus.com/bid/29508
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause it fails to adequately handle specially crafted PGM (Pragmatic Gene=
ral Multicast) network traffic.
Attackers can exploit this issue to cause an affected computer to stop re=
sponding until it is manually restarted. Successful attacks will deny ser=
vice to legitimate users.=20
NOTE: PGM is enabled only when Microsoft Message Queuing (MSMQ) 3.0 is in=
stalled on computers running Windows XP and Windows Server 2003. The MSM=
Q service is not installed by default. Supported editions of Windows Serv=
er 2008 are not affected if installed using the Server Core installation =
option.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. default for requiring authentication 2003
http://www.securityfocus.com/archive/88/493298
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Black Hat USA:
Attend Black Hat USA, August 2-7 in Las Vegas, the world's premier techni=
cal event for ICT security experts. Featuring 40 hands-on training course=
s and 80 Briefings presentations with lots of new content and new tools. =
Network with 4,000 delegates from 50 nations. Visit product displays by=
30 top sponsors in a relaxed setting.=20
www.blackhat.com