SecurityFocus Microsoft Newsletter #412

[email protected] 17 Sep 2008 22:22:36 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #412
----------------------------------------

This issue is sponsored by Sponsored by Ironkey: The World's Most Secure =
Flash Drive

IronKey flash dives lock down your most sensitive data using today's most=
 advanced security technology.=20
IronKey uses military-grade AES CBC-mode hardware encryption that cannot =
be disabled by malware or an intruder and provides rugged and waterproof =
protection to safeguard your data.
https://www.ironkey.com/forenterprise2


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.SATAN'S Helper
       2.Get Off My Cloud
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Microsoft Internet Explorer Malfromed PNG File Remote Denial of=
 Service Vulnerability
       2. Adobe Illustrator Malformed AI File Remote Code Execution Vulne=
rability
       3. Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vu=
lnerability
       4. Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Se=
rvice Vulnerability
       5. Personal FTP Server 'RETR' Command Remote Denial of Service Vul=
nerability
       6. Baidu Hi 'CSTransfer.dll' Remote Stack Buffer Overflow Vulnerab=
ility
       7. Avant Browser JavaScript Engine Integer Overflow Vulnerability
       8. RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer=
 Overflow Vulnerability
       9. ZoneAlarm Security Suite AntiVirus Directory Path Buffer Overfl=
ow Vulnerability
       10. Maxthon Browser Remote Denial of Service Vulnerability
       11. Apple iTunes Misleading Firewall Warning Weakness
       12. Apple iTunes Third Party Driver Local Privilege Escalation Vul=
nerability
       13. Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilitie=
s
       14. Microsoft Windows Image Acquisition Logger ActiveX Control Arb=
itrary File Overwrite Vulnerability
       15. Microsoft Office OneNote URL Handler Remote Code Execution Vul=
nerability
       16. Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control R=
emote Buffer Overflow Vulnerability
       17. Microsoft Organization Chart Remote Code Execution Vulnerabili=
ty
       18. Microsoft GDI+ BMP Integer Overflow Vulnerability
       19. Microsoft GDI+ WMF Image File Buffer Overflow Vulnerability
       20. Microsoft GDI+ GIF File Parsing Remote Code Execution Vulnerab=
ility
       21. Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerab=
ility
       22. Microsoft GDI+ VML Heap-Based Buffer Overflow Vulnerability
       23. Microsoft Windows Media Player SSPL File Sample Rate Remote Co=
de-Execution Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #411
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.SATAN's Helper
By Federico Biancuzzi
SecurityFocus contributor Federico Biancuzzi chatted up Venema to talk ab=
out software security, how to improve the code quality, what solutions we=
 might have to fight spam successfully, the principle of least privilege,=
 and the philosophy behind the design of Postfix.=20
Venema is currently a researcher at IBM's T.J. Watson Research Center
http://www.securityfocus.com/columnists/479

2.Get Off My Cloud
By Mark Rasch
One of the features of Apple's device that appeals to me is the new Mobil=
eMe service, where you can "access and manage your email, contacts, calen=
dar, photos, and files at me.com," according to Apple.=20
More companies, among them Microsoft and Google, already allow people to =
store information and use common services online -- or "in the cloud" -- =
leading analysts to refer to the entire trend as "cloud computing."
http://www.securityfocus.com/columnists/478


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Microsoft Internet Explorer Malfromed PNG File Remote Denial of Servic=
e Vulnerability
BugTraq ID: 31215
Remote: Yes
Date Published: 2008-09-17
Relevant URL: http://www.securityfocus.com/bid/31215
Summary:
Microsoft Internet Explorer is prone to a remote denial-of-service vulner=
ability.=20

Attackers can exploit this issue by enticing an unsuspecting victim to vi=
ew a web page embedded with a malicious PNG file.=20

Successfully exploiting this issue will cause the application to stop res=
ponding, denying service to legitimate users.

Microsoft Internet Explorer 7 and 8 Beta 1 are vulnerable; other versions=
 may also be affected.

2. Adobe Illustrator Malformed AI File Remote Code Execution Vulnerabilit=
y
BugTraq ID: 31208
Remote: Yes
Date Published: 2008-09-16
Relevant URL: http://www.securityfocus.com/bid/31208
Summary:
Adobe Illustrator is prone to a remote code-execution vulnerability.=20

An attacker can exploit this issue by enticing an unsuspecting victim to =
open a malicious AI file.

Successfully exploiting this issue will allow attackers to execute arbitr=
ary code with the privileges of the user running the affected application=
.=20

This issue affects only Adobe Illustrator CS2 for Macintosh.

3. Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerabi=
lity
BugTraq ID: 31204
Remote: Yes
Date Published: 2008-09-16
Relevant URL: http://www.securityfocus.com/bid/31204
Summary:
Acresso FLEXnet Connect is prone to a remote code-execution vulnerability=
 because it fails to adequately verify the authenticity of files obtained=
 from update servers. The product has been formerly available as Macrovis=
ion FLEXnet Connect and as InstallShield Update Service.

Attackers can exploit this issue by performing man-in-the-middle attacks =
to have the client download and execute a malicious file hosted on an att=
acker-controlled computer. Other attacks may also be possible.

Acresso FLEXnet Connect is vulnerable. Additional products that use the F=
LEXnet functionality may also be vulnerable.

4. Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service V=
ulnerability
BugTraq ID: 31179
Remote: Yes
Date Published: 2008-09-15
Relevant URL: http://www.securityfocus.com/bid/31179
Summary:
Microsoft Windows is prone to a remote denial-of-service vulnerability be=
cause it fails to adequately handle specially crafted SMB packets.

Attackers can exploit this issue to cause an affected computer to stop re=
sponding, denying service to legitimate users. Given the nature of this i=
ssue, attackers may also be able to run arbitrary code with SYSTEM-level =
privileges, but this has not been confirmed.

5. Personal FTP Server 'RETR' Command Remote Denial of Service Vulnerabil=
ity
BugTraq ID: 31173
Remote: Yes
Date Published: 2008-09-14
Relevant URL: http://www.securityfocus.com/bid/31173
Summary:
Personal FTP Server is prone to a remote denial-of-service vulnerability =
because the application fails to handle exceptional conditions.=20

Successfully exploiting this issue would cause the affected application t=
o crash, denying service to legitimate users.

Personal FTP Server 6.0f is vulnerable; other versions may also be affect=
ed.

6. Baidu Hi 'CSTransfer.dll' Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 31162
Remote: Yes
Date Published: 2008-09-13
Relevant URL: http://www.securityfocus.com/bid/31162
Summary:
Baidu Hi is prone to a remote stack-based buffer-overflow vulnerability b=
ecause the application fails to bounds-check user-supplied data before co=
pying it into an insufficiently sized buffer.=20

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial of service.

7. Avant Browser JavaScript Engine Integer Overflow Vulnerability
BugTraq ID: 31155
Remote: Yes
Date Published: 2008-09-12
Relevant URL: http://www.securityfocus.com/bid/31155
Summary:
Avant Browser is prone to an integer-overflow vulnerability that occurs i=
n the JavaScript engine.

An attacker can exploit this issue by enticing an unsuspecting victim to =
view a malicious site.=20

Successfully exploiting this issue may allow attackers to crash the affec=
ted application, denying service to legitimate users. Given the nature of=
 this issue, attackers may also be able to run arbitrary code, but this h=
as not been confirmed.

Avant Browser 11.7 Build 9 is vulnerable; other versions may also be affe=
cted.

NOTE: This vulnerability may be related to the issue described in BID 149=
17 (Mozilla Browser/Firefox JavaScript Engine Integer Overflow Vulnerabil=
ity).

8. RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overfl=
ow Vulnerability
BugTraq ID: 31129
Remote: Yes
Date Published: 2008-09-11
Relevant URL: http://www.securityfocus.com/bid/31129
Summary:
Microsoft SQL Server 'sqlvdir.dll' ActiveX Control is prone to a buffer-o=
verflow vulnerability because it fails to bounds-check user-supplied data=
 before copying it into an insufficiently sized buffer.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.

 This control is included with Microsoft SQL Server 2000; other versions =
may also be affected.

NOTE: This BID is being retired because the issue is not exploitable. The=
 ActiveX control is not marked 'Safe for Scripting'.

9. ZoneAlarm Security Suite AntiVirus Directory Path Buffer Overflow Vuln=
erability
BugTraq ID: 31124
Remote: Yes
Date Published: 2008-09-11
Relevant URL: http://www.securityfocus.com/bid/31124
Summary:
ZoneAlarm Security Suite is prone to a buffer-overflow vulnerability beca=
use the application fails to perform adequate boundary checks on user-sup=
plied input when performing virus scans on long directory paths.

Remote attackers may leverage this issue to execute arbitrary code with S=
YSTEM-level privileges and gain complete access to the vulnerable compute=
r. Failed attacks will cause denial-of-service conditions.

This issue affects ZoneAlarm Security Suite 7.0.483.000; other versions m=
ay also be affected.

10. Maxthon Browser Remote Denial of Service Vulnerability
BugTraq ID: 31098
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31098
Summary:
Maxthon Browser is prone to a denial-of-service vulnerability.=20

An attacker may exploit this issue by enticing victims into opening a mal=
iciously crafted webpage.

 Successfully exploiting this issue will allow the attacker to crash the =
application, denying service to legitimate users.=20

This issue affects Maxthon Browser 2.1.4.443; other versions may also be =
affected.

11. Apple iTunes Misleading Firewall Warning Weakness
BugTraq ID: 31090
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31090
Summary:
Apple iTunes is prone to a weakness caused by a misleading firewall warni=
ng that conveys erroneous information to users.

This issue may lead to a false sense of security, potentially aiding in n=
etwork-based attacks.

Versions prior to Apple iTunes 8.0 are vulnerable to this issue.

12. Apple iTunes Third Party Driver Local Privilege Escalation Vulnerabil=
ity
BugTraq ID: 31089
Remote: No
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31089
Summary:
Apple iTunes is prone to a local privilege-escalation vulnerability due t=
o an integer-overflow issue.=20

Local attackers can exploit this issue to execute arbitrary code with SYS=
TEM-level privileges. Successfully exploiting this issue will result in t=
he complete compromise of affected computers. Failed exploit attempts wil=
l cause a denial-of-service condition.

This issue affects versions prior to iTunes 8.0 for Microsoft Windows XP =
and Microsoft Windows Vista.

13. Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities
BugTraq ID: 31086
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31086
Summary:
Apple QuickTime is prone to multiple remote vulnerabilities that may allo=
w remote attackers to execute arbitrary code and carry out denial-of-serv=
ice attacks.

These issues arise when the application handles specially crafted PICT im=
age files, movies, and QTVR movies. Successful exploits may allow attacke=
rs to gain remote unauthorized access in the context of a vulnerable user=
 and to trigger a denial-of-service condition.

Versions prior to QuickTime 7.5.5 are affected.

14. Microsoft Windows Image Acquisition Logger ActiveX Control Arbitrary =
File Overwrite Vulnerability
BugTraq ID: 31069
Remote: Yes
Date Published: 2008-09-08
Relevant URL: http://www.securityfocus.com/bid/31069
Summary:
Microsoft Windows Image Acquisition Logger ActiveX control is prone to a =
vulnerability that lets attackers overwrite files with arbitrary, attacke=
r-controlled content. The issue occurs because the control fails to sanit=
ize user-supplied input.

An attacker can exploit this issue to overwrite files with attacker-suppl=
ied data, which will aid in further attacks.

15. Microsoft Office OneNote URL Handler Remote Code Execution Vulnerabil=
ity
BugTraq ID: 31067
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31067
Summary:
Microsoft Office OneNote is prone to a remote code-execution vulnerabilit=
y.

An attacker could exploit this issue by enticing a victim to follow malic=
iously crafted URIs.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

16. Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote B=
uffer Overflow Vulnerability
BugTraq ID: 31065
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31065
Summary:
The Microsoft Windows Media Encoder 9 ActiveX control is prone to a buffe=
r-overflow vulnerability because it fails to perform adequate boundary ch=
ecks on user-supplied input.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of an application using the affected ActiveX control (typically Intern=
et Explorer). Failed attacks will likely cause denial-of-service conditio=
ns.

17. Microsoft Organization Chart Remote Code Execution Vulnerability
BugTraq ID: 31059
Remote: Yes
Date Published: 2008-09-08
Relevant URL: http://www.securityfocus.com/bid/31059
Summary:
Microsoft Organization Chart is prone to a remote code-execution vulnerab=
ility because of a memory-access violation.

Remote attackers can exploit this issue by enticing victims into opening =
a maliciously crafted Organization Chart document.

Successful exploits may allow attackers to execute arbitrary code within =
the context of the affected application. Failed exploit attempts will lik=
ely result in a denial of service.

Microsoft Organization Chart 2.00,19 is vulnerable; other versions may al=
so be affected.

18. Microsoft GDI+ BMP Integer Overflow Vulnerability
BugTraq ID: 31022
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31022
Summary:
Microsoft GDI+ is prone to an integer-overflow vulnerability.

An attacker can exploit this issue by enticing unsuspecting users to view=
 a malicious BMP file.

Successfully exploiting this issue allows remote attackers to corrupt mem=
ory and execute arbitrary code in the context of the affected application=
. Failed exploit attempts will result in a denial-of-service condition.

19. Microsoft GDI+ WMF Image File Buffer Overflow Vulnerability
BugTraq ID: 31021
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31021
Summary:
Microsoft GDI+ is prone to a buffer-overflow vulnerability because the ve=
ctor graphics linked library improperly allocates memory when parsing WMF=
 image files.

Successfully exploiting this issue would allow an attacker to corrupt mem=
ory and execute arbitrary code in the context of the currently logged-in =
user.

20. Microsoft GDI+ GIF File Parsing Remote Code Execution Vulnerability
BugTraq ID: 31020
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31020
Summary:
Microsoft GDI+ is prone to a remote code-execution vulnerability because =
the vector graphics link library improperly parses GIF image files.

An attacker could exploit this issue to execute arbitrary code with the p=
rivileges of the currently logged-in user. Failed exploit attempts may cr=
ash applications that use the library.

21. Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability
BugTraq ID: 31019
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31019
Summary:
Microsoft GDI+ is prone to a remote memory-corruption vulnerability that =
occurs when an application that uses the library tries to process a speci=
ally crafted EMF (Enhanced Metafile) image file.

Successfully exploiting this issue would allow an attacker to execute arb=
itrary code in the context of the currently logged-in user.

22. Microsoft GDI+ VML Heap-Based Buffer Overflow Vulnerability
BugTraq ID: 31018
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/31018
Summary:
Microsoft GDI+ is prone to a heap-based buffer-overflow vulnerability bec=
ause the vector graphics link library improperly processes gradient sizes=
.

Successfully exploiting this issue would allow an attacker to corrupt hea=
p memory and execute arbitrary code in the context of the currently logge=
d-in user.

23. Microsoft Windows Media Player SSPL File Sample Rate Remote Code-Exec=
ution Vulnerability
BugTraq ID: 30550
Remote: Yes
Date Published: 2008-09-09
Relevant URL: http://www.securityfocus.com/bid/30550
Summary:
Microsoft Windows Media Player is prone to a remote code-execution vulner=
ability.

An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.

NOTE: Supported editions of Windows Server 2008 are not affected if insta=
lled using the Server Core installation option.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #411
http://www.securityfocus.com/archive/88/496270

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Sponsored by Ironkey: The World's Most Secure =
Flash Drive

IronKey flash dives lock down your most sensitive data using today's most=
 advanced security technology.=20
IronKey uses military-grade AES CBC-mode hardware encryption that cannot =
be disabled by malware or an intruder and provides rugged and waterproof =
protection to safeguard your data.
https://www.ironkey.com/forenterprise2