SecurityFocus Microsoft Newsletter #416

[email protected] 16 Oct 2008 22:05:43 -0000
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #416
----------------------------------------

This issue is sponsored by HP:

Download a FREE trial of HP WebInspect
Application attacks are growing more prevalent. New attacks are in the ne=
ws each day. Now it's time for you to assess your applications and start =
detecting and removing vulnerabilities.=20
HP can help, with a full suite of application security solutions.  Get st=
arted today with a complimentary trial download that uses an HP test appl=
ication. Thoroughly analyze today's complex web applications in a runtime=
 environment with fast scanning capabilities, broad assessment coverage a=
nd accurate web application scanning results.=20
Download WebInspect now:=20

https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=3DdownloadBinSta=
rt&zn=3Dbto&cp=3D54_4012_100__&caid=3D14563&jumpid=3Dex_r11374_us/en/larg=
e/tsg/WebInspect_Eval_Secutiy_Focus/3-1QN6MII_3-UTM2ZJ/20081015&origin_id=
=3D3-1QN6MII


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1.The Vice of Vice Presidential E-Mail
       2.Blaming the Good Samaritan
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' =
Buffer Overflow Vulnerability
       2. Adobe Flash CS3 Professional SWF File Heap Buffer Overflow Vuln=
erability
       3. Microsoft Outlook Web Access for Exchange Server 'redir.asp' UR=
I Redirection Vulnerability
       4. Titan FTP Server 'SITE WHO' Command Remote Denial of Service Vu=
lnerability
       5. Etype Eserv FTP 'ABOR' Command Remote Stack Based Buffer Overfl=
ow Vulnerability
       6. Husdawg System Requirements Lab Multiple Remote Code Execution =
Vulnerabilities
       7. RaidenFTPD 'MLST' Command Remote Stack Based Buffer Overflow Vu=
lnerability
       8. XM Easy Personal FTP Server 'NSLT' Command Remote Denial of Ser=
vice Vulnerability
       9. Lenovo Rescue and Recovery 'tvtumon.sys' Heap Overflow Vulnerab=
ility
       10. Apple OS X QuickLook Excel File Integer Overflow Vulnerability
       11. Microsoft Excel Formula Parsing Remote Code Execution Vulnerab=
ility
       12. Microsoft Excel BIFF File Format Parsing Remote Code Execution=
 Vulnerability
       13. Microsoft Excel Calendar Object Validation Remote Code Executi=
on Vulnerability
       14. NoticeWare Email Server NG 'PASS' Command Remote Denial of Ser=
vice Vulnerability
       15. Microsoft Office CDO Protocol Cross Site Scripting Vulnerabili=
ty
       16. Win FTP Server 'NLIST' Command Remote Denial of Service Vulner=
ability
       17. Computer Associates ARCserve Backup Multiple Remote Vulnerabil=
ities
       18. Microsoft Windows Internet Printing Service Integer Overflow V=
ulnerability
       19. RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabili=
ties
       20. Microsoft Windows VAD Local Privilege Escalation Vulnerability
       21. Microsoft Windows AFD Driver Local Privilege Escalation Vulner=
ability
       22. Microsoft October 2008 Advance Notification Multiple Vulnerabi=
lities
       23. Drupal Multiple Modules Security Bypass Vulnerabilities
       24. Microsoft Internet Explorer Cross Domain Information Disclosur=
e Vulnerability
       25. Microsoft Windows Kernel Unhandled System Call Local Privilege=
 Escalation Vulnerability
       26. Microsoft Windows Kernel Memory Corruption Local Privilege Esc=
alation Vulnerability
       27. Microsoft Windows Kernel Window Creation Local Privilege Escal=
ation Vulnerability
       28. Microsoft Windows SMB Buffer Underflow Code Execution Vulnerab=
ility
       29. Cisco Unity 7.0 Multiple Remote Vulnerabilities
       30. Cisco Unity Remote Administration Authentication Bypass Vulner=
ability
       31. Microsoft Message Queuing Service RPC Query Heap Corruption Vu=
lnerability
       32. Avaya one-X Desktop Edition SIP Remote Denial Of Service Vulne=
rability
       33. Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitra=
ry File Download Vulnerability
       34. Microsoft Host Integration Server RPC Remote Command Execution=
 Vulnerability
       35. Microsoft Internet Explorer HTML Objects Uninitialized Memory =
Corruption Vulnerability
       36. Microsoft Internet Explorer Uninitialized Object Remote Memory=
 Corruption Vulnerability
       37. Microsoft Internet Explorer Event Handling Cross Domain Securi=
ty Bypass Vulnerability
       38. Microsoft Internet Explorer HTML Element Cross Domain Security=
 Bypass Vulnerability
       39. Mozilla Firefox Internet Shortcut Same Origin Policy Violation=
 Vulnerability
       40. Microsoft Windows Active Directory LDAP Request Handling Remot=
e Code Execution Vulnerability
       41. Internet Download Manager File Parsing Buffer Overflow Vulnera=
bility
       42. MetaGauge Web Server Directory Traversal Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #415
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.The Vice of Vice Presidential E-Mail
By Mark Rasch
Seems like a simple question, but the law is not so clear. In mid-Septemb=
er 2008, a hacker using the handle "Rubico" claim credit for breaking int=
o the Yahoo! e-mail account of Governor Sarah Palin, the Republican Vice =
Presidential candidate. In a post online, Rubico wrote that he had been f=
ollowing news reports that claimed Palin had been using her personal Yaho=
o e-mail account for official government business.
http://www.securityfocus.com/columnists/482

2.Blaming the Good Samaritan
By Houston Carr
In the early 90's, I attended an academic conference in Hawaii. At one pr=
esentation, a colleague from the University of California at Berkeley who=
m I'll refer to as "the supervisor," told a story of young hackers, who h=
e referred to as the Urchins
http://www.securityfocus.com/columnists/481


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Hummingbird HostExplorer ActiveX Control 'PlainTextPassword()' Buffer =
Overflow Vulnerability
BugTraq ID: 31783
Remote: Yes
Date Published: 2008-10-16
Relevant URL: http://www.securityfocus.com/bid/31783
Summary:
Hummingbird HostExplorer  ActiveX control is prone to a buffer-overflow v=
ulnerability because the application fails to adequately check boundaries=
 on user-supplied input.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the application using the ActiveX control (typically Internet Explo=
rer).  Failed attacks will likely cause denial-of-service conditions.

2. Adobe Flash CS3 Professional SWF File Heap Buffer Overflow Vulnerabili=
ty
BugTraq ID: 31769
Remote: Yes
Date Published: 2008-10-15
Relevant URL: http://www.securityfocus.com/bid/31769
Summary:
Adobe Flash CS3 Professional is prone to a heap-buffer overflow vulnerabi=
lity.

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Failed exploit attempts will likely resul=
t in denial-of-service conditions.

Flash CS3 Professional for Microsoft Windows is vulnerable.

3. Microsoft Outlook Web Access for Exchange Server 'redir.asp' URI Redir=
ection Vulnerability
BugTraq ID: 31765
Remote: Yes
Date Published: 2008-10-15
Relevant URL: http://www.securityfocus.com/bid/31765
Summary:
Outlook Web Access is prone to a remote URI-redirection vulnerability bec=
ause the application fails to properly sanitize user-supplied input.=20

A successful exploit may aid in phishing attacks.

OWA 6.5 SP 2 is vulnerable; other versions may also be affected.

4. Titan FTP Server 'SITE WHO' Command Remote Denial of Service Vulnerabi=
lity
BugTraq ID: 31757
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31757
Summary:
Titan FTP Server is prone to a remote denial-of-service vulnerability.

This issue allows remote attackers to crash affected FTP servers, denying=
 service to legitimate users.

Titan FTP Server 6.26 build 630 is vulnerable; other versions may also be=
 affected.

5. Etype Eserv FTP 'ABOR' Command Remote Stack Based Buffer Overflow Vuln=
erability
BugTraq ID: 31753
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31753
Summary:
Etype Eserv is prone to a remote stack-based buffer-overflow vulnerabilit=
y.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

Eserv 3.26 is vulnerable; other versions may also be affected.

6. Husdawg System Requirements Lab Multiple Remote Code Execution Vulnera=
bilities
BugTraq ID: 31752
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31752
Summary:
Husdawg System Requirements Lab ActiveX controls and Java applets are pro=
ne to multiple remote code-execution vulnerabilities.

Successful exploit will allow attackers to download and execute arbitrary=
 files on the affected computer in the context of the application that us=
es the plugins.

7. RaidenFTPD 'MLST' Command Remote Stack Based Buffer Overflow Vulnerabi=
lity
BugTraq ID: 31741
Remote: Yes
Date Published: 2008-10-13
Relevant URL: http://www.securityfocus.com/bid/31741
Summary:
RaidenFTPD is prone to a remote stack-based buffer-overflow vulnerability=
.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

RaidenFTPD 2.4 build 3620 is vulnerable; other versions may also be affec=
ted.

8. XM Easy Personal FTP Server 'NSLT' Command Remote Denial of Service Vu=
lnerability
BugTraq ID: 31739
Remote: Yes
Date Published: 2008-10-13
Relevant URL: http://www.securityfocus.com/bid/31739
Summary:
XM Easy Personal FTP Server is prone to a remote denial-of-service vulner=
ability.

This issue allows remote attackers to crash affected FTP servers, denying=
 service to legitimate users.

XM Easy Personal FTP Server 5.6.0 is vulnerable; other versions may also =
be affected.

9. Lenovo Rescue and Recovery 'tvtumon.sys' Heap Overflow Vulnerability
BugTraq ID: 31737
Remote: No
Date Published: 2008-10-13
Relevant URL: http://www.securityfocus.com/bid/31737
Summary:
Lenovo Rescue and Recovery is prone to a heap-based overflow vulnerabilit=
y.

A successful exploit of this vulnerability can allow a local attacker to =
completely compromise the affected computer.

Lenovo Rescue and Recover 4.20 is vulnerable.

10. Apple OS X QuickLook Excel File Integer Overflow Vulnerability
BugTraq ID: 31707
Remote: Yes
Date Published: 2008-10-09
Relevant URL: http://www.securityfocus.com/bid/31707
Summary:
Apple OS X QuickLook is prone to an integer-overflow vulnerability becaus=
e it fails to perform adequate boundary checks on user-supplied input. Sp=
ecifically, this issue is related to the handling of Microsoft Excel spre=
adsheet files.

Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of  the application. Failed exploit attempt=
s will cause denial-of-service conditions.

NOTE: This issue was previously covered in BID 31681 (Apple Mac OS X 2008=
-007 Multiple Security Vulnerabilities) but has been given its own record=
 to better document this vulnerability.

11. Microsoft Excel Formula Parsing Remote Code Execution Vulnerability
BugTraq ID: 31706
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31706
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

12. Microsoft Excel BIFF File Format Parsing Remote Code Execution Vulner=
ability
BugTraq ID: 31705
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31705
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

13. Microsoft Excel Calendar Object Validation Remote Code Execution Vuln=
erability
BugTraq ID: 31702
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31702
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

14. NoticeWare Email Server NG 'PASS' Command Remote Denial of Service Vu=
lnerability
BugTraq ID: 31697
Remote: Yes
Date Published: 2008-10-10
Relevant URL: http://www.securityfocus.com/bid/31697
Summary:
NoticeWare Email Server NG is prone to a remote denial-of-service vulnera=
bility.

Exploiting this issue allows remote attackers to crash the application, d=
enying service to legitimate users.=20

This issue affects NoticeWare Email Server NG 5.1.2.2; other versions may=
 also be vulnerable.

15. Microsoft Office CDO Protocol Cross Site Scripting Vulnerability
BugTraq ID: 31693
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31693
Summary:
Microsoft Office is prone to a cross-site scripting vulnerability that ar=
ises because the software fails to handle specially crafted CDO protocol =
URIs in a proper manner.

Successfully exploiting this issue may allow an attacker to execute arbit=
rary script code in the browser of an unsuspecting user in the context of=
 the affected site. This may allow the attacker to steal cookie-based aut=
hentication credentials and to launch other attacks.

Office XP Service Pack 3 is vulnerable.

16. Win FTP Server 'NLIST' Command Remote Denial of Service Vulnerability
BugTraq ID: 31686
Remote: Yes
Date Published: 2008-10-09
Relevant URL: http://www.securityfocus.com/bid/31686
Summary:
Win FTP Server is prone to a remote denial-of-service vulnerability.

Exploiting this issue allows remote attackers to crash the application, d=
enying service to legitimate users.=20

This issue affects Win FTP  2.0.2; other versions may also be vulnerable.

17. Computer Associates ARCserve Backup Multiple Remote Vulnerabilities
BugTraq ID: 31684
Remote: Yes
Date Published: 2008-10-09
Relevant URL: http://www.securityfocus.com/bid/31684
Summary:
Computer Associates ARCserve Backup is prone to multiple remote vulnerabi=
lities.

Successful exploits allow remote attackers to cause denial-of-service con=
ditions or to execute arbitrary commands in the context of the affected a=
pplication. This may result in a complete compromise of affected computer=
s.

The following applications are affected:
=20
CA BrightStor ARCserve Backup r11.1, r11.5, r12.0 for Windows
 CA Server Protection Suite r2
 CA Business Protection Suite r2
 CA Business Protection Suite for Microsoft Small Business Server Standar=
d Edition r2
 CA Business Protection Suite for Microsoft Small Business Server Premium=
 Edition r2

18. Microsoft Windows Internet Printing Service Integer Overflow Vulnerab=
ility
BugTraq ID: 31682
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31682
Summary:
Microsoft Internet Printing Service is prone to an integer-overflow vulne=
rability.

Exploiting this vulnerability allows attackers to execute arbitrary code =
with the privileges of the user running the affected service.

19. RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabilities
BugTraq ID: 31681
Remote: Yes
Date Published: 2008-10-09
Relevant URL: http://www.securityfocus.com/bid/31681
Summary:
Apple Mac OS X is prone to multiple security vulnerabilities that have be=
en addressed in Security Update 2008-007.

The security update addresses a total of 11 new vulnerabilities that affe=
ct the ColorSync, CUPS, Finder, launchd, Networking, Postfix, PSNormalize=
r, rlogin, Script Editor, and Weblog components of Mac OS X. The advisory=
 also contains security updates for 30 previously reported issues.

NOTE: This BID is being retired; the following individual records have be=
en created to better document these issues:

31716 Apple Script Editor Unspecified Insecure Temporary File Creation Vu=
lnerability
31718 Apple Mac OS X Server Weblog Access Control List Security Bypass Vu=
lnerability
31708 Apple Mac OS X 'hosts.equiv' Security Bypass Vulnerability
31721 Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
31719 Apple PSNormalizer PostScript Buffer Overflow Vulnerability
31711 Apple Mac OS X 'configd' EAPOLController Plugin Local Heap Based Bu=
ffer Overflow Vulnerability
31715 Apple Mac OS X ColorSync ICC Profile Remote Buffer Overflow Vulnera=
bility
31720 Apple Finder Denial of Service Vulnerability
31707 Apple OS X QuickLook Excel File Integer Overflow Vulnerability
31688 CUPS 'HP-GL/2' Filter Remote Code Execution Vulnerability
31722 Apple Mac OS X 10.5 'launchd' Unspecified Security Bypass Vulnerabi=
lity

20. Microsoft Windows VAD Local Privilege Escalation Vulnerability
BugTraq ID: 31675
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31675
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
because of an error in how the system memory manager handles memory alloc=
ation in relation to Virtual Address Descriptors (VAD).=20

A successful exploit will let a local attacker completely compromise an a=
ffected computer.

21. Microsoft Windows AFD Driver Local Privilege Escalation Vulnerability
BugTraq ID: 31673
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31673
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
in the Ancillary Function Driver ('afd.sys').

A successful exploit of this vulnerability will let a local attacker comp=
letely compromise an affected computer.

22. Microsoft October 2008 Advance Notification Multiple Vulnerabilities
BugTraq ID: 31667
Remote: Yes
Date Published: 2008-10-09
Relevant URL: http://www.securityfocus.com/bid/31667
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing eleven security bulletins on October 14, 2008. The highest severity =
rating for these issues is 'Critical'.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

Individual records will be created to better document these issues when t=
he bulletins are released.

23. Drupal Multiple Modules Security Bypass Vulnerabilities
BugTraq ID: 31660
Remote: Yes
Date Published: 2008-10-08
Relevant URL: http://www.securityfocus.com/bid/31660
Summary:
Multiple Drupal Modules are prone to security-bypass vulnerabilities that=
 may allow attackers to gain access to administrative or sensitive areas =
of the application without the appropriate privileges.

 These issues affect versions prior to the following:

Live module 6.x-1.0
AJAX Picture Preview module 6.x-1.2
Admin:hover module 6.x-1.x-dev before 2008-Oct-08
Banner Rotor Module 6.x-1.3
Creative Commons Lite 6.x-1.1
Keyboard shortcut utilty 6.x-1.1
LiveJournal CrossPoster 6.x-1.4
Taxonomy import/export via XML 6.x-1.2
User Referral 6.x-1.x-dev before 2008-Oct-08

24. Microsoft Internet Explorer Cross Domain Information Disclosure Vulne=
rability
BugTraq ID: 31654
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31654
Summary:
Microsoft Internet Explorer is prone to a cross-domain information-disclo=
sure vulnerability because the application fails to properly enforce the =
same-origin policy.

An attacker can exploit this issue to execute arbitrary script code in an=
other browser window's security zone. This may allow the attacker to stea=
l cookie-based authentication credentials and launch other attacks.

25. Microsoft Windows Kernel Unhandled System Call Local Privilege Escala=
tion Vulnerability
BugTraq ID: 31653
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31653
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

26. Microsoft Windows Kernel Memory Corruption Local Privilege Escalation=
 Vulnerability
BugTraq ID: 31652
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31652
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

27. Microsoft Windows Kernel Window Creation Local Privilege Escalation V=
ulnerability
BugTraq ID: 31651
Remote: No
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31651
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability.=
=20

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

28. Microsoft Windows SMB Buffer Underflow Code Execution Vulnerability
BugTraq ID: 31647
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31647
Summary:
Microsoft Windows is prone to a remote code execution vulnerability. This=
 is due to a buffer underflow condition in the SMB (Server Message Block)=
 protocol implementation.

To exploit the issue, the attacker must first successfully authenticate a=
s a legitimate user or a Guest user on the affected computer. A successfu=
l exploit will completely compromise the affected computer.

29. Cisco Unity 7.0 Multiple Remote Vulnerabilities
BugTraq ID: 31642
Remote: Yes
Date Published: 2008-10-08
Relevant URL: http://www.securityfocus.com/bid/31642
Summary:
Cisco Unity is prone to multiple remote vulnerabilities, including:

- An information-disclosure vulnerability in the web interface
- A denial-of-service vulnerability in the administration interface
- A script-injection vulnerability in the web interface
- Multiple denial-of-service vulnerabilities in unspecified services

These issues are reported in Cisco Unity 7.0; other versions may also be =
affected.

30. Cisco Unity Remote Administration Authentication Bypass Vulnerability
BugTraq ID: 31638
Remote: Yes
Date Published: 2008-10-08
Relevant URL: http://www.securityfocus.com/bid/31638
Summary:
Cisco Unity is prone to an authentication-bypass vulnerability.

Exploiting this issue can allow remote attackers to gain unauthorized adm=
inistrative privileges. This issue is being tracked by Cisco Bug ID CSCsr=
86943.

Versions prior to the following are vulnerable:
=20
 Cisco Unity 4.0 ES161 for the 4.x release
 Cisco Unity 5.0 ES53 for the 5.x release
 Cisco Unity 7.0 ES8 for the   7.x release

31. Microsoft Message Queuing Service RPC Query Heap Corruption Vulnerabi=
lity
BugTraq ID: 31637
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31637
Summary:
The Microsoft Message Queuing service (MSMQ) is prone to a remote heap-co=
rruption vulnerability.

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges, facilitating the complete compromise of an affected com=
puter. Failed exploit attempts will result in a denial-of-service conditi=
on.  =20

This issue is exploitable remotely on Windows 2000 systems only. The MSMQ=
 service is not installed or enabled by default. For  a computer to be ex=
ploited, an administrator must have explicitly installed and enabled the =
service.

32. Avaya one-X Desktop Edition SIP Remote Denial Of Service Vulnerabilit=
y
BugTraq ID: 31636
Remote: Yes
Date Published: 2008-10-08
Relevant URL: http://www.securityfocus.com/bid/31636
Summary:
Avaya one-X Desktop Edition phone is prone to a remote denial-of-service =
vulnerability.

An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.

Avaya one-X Desktop Edition 2.1 is vulnerable; other versions may also be=
 affected.

33. Microsoft PicturePusher 'PipPPush.dll' ActiveX Control Arbitrary File=
 Download Vulnerability
BugTraq ID: 31632
Remote: Yes
Date Published: 2008-10-08
Relevant URL: http://www.securityfocus.com/bid/31632
Summary:
Microsoft PicturePusher ActiveX control  in 'PipPPush.dll' is prone to a =
vulnerability that lets attackers download arbitrary files.

Attackers may exploit this issue by enticing victims into visiting a mali=
ciously crafted webpage.
=20
Successful exploits will allow remote attackers to download files from ar=
bitrary locations to the affected computer.

The affected ActiveX control may be a component of Microsoft Digital Imag=
e 2006 Starter Edition. =20

'PipPPush.dll' 7.00.0709 is vulnerable; other versions may also be affect=
ed.

34. Microsoft Host Integration Server RPC Remote Command Execution Vulner=
ability
BugTraq ID: 31620
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31620
Summary:
Microsoft Windows is prone to a remote command-execution vulnerability in=
 the SNA service through a remote procedure call (RPC).

Successfully exploiting this issue would allow an attacker to execute arb=
itrary commands on an affected computer in the context of the affected se=
rvice.

35. Microsoft Internet Explorer HTML Objects Uninitialized Memory Corrupt=
ion Vulnerability
BugTraq ID: 31618
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31618
Summary:
Microsoft Internet Explorer is prone to a remote memory-corruption vulner=
ability.=20

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

36. Microsoft Internet Explorer Uninitialized Object Remote Memory Corrup=
tion Vulnerability
BugTraq ID: 31617
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31617
Summary:
Microsoft Internet Explorer is prone to a remote memory-corruption vulner=
ability.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

37. Microsoft Internet Explorer Event Handling Cross Domain Security Bypa=
ss Vulnerability
BugTraq ID: 31616
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31616
Summary:
Microsoft Internet Explorer is prone to a cross-domain security-bypass vu=
lnerability because the application fails to properly enforce the same-or=
igin policy.

An attacker can exploit this issue to execute arbitrary script code in an=
other browser window's security zone. This may allow attackers to steal c=
ookie-based authentication credentials and launch other attacks.

NOTE: Attackers exploiting this issue on Internet Explorer 6 SP1 running =
on Microsoft Windows 2000 SP4 may leverage the issue to execute remote co=
de. Other vulnerable versions of the browser are prone only to informatio=
n disclosure.

38. Microsoft Internet Explorer HTML Element Cross Domain Security Bypass=
 Vulnerability
BugTraq ID: 31615
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31615
Summary:
Microsoft Internet Explorer is prone to a cross-domain security-bypass vu=
lnerability because the application fails to properly enforce the same-or=
igin policy.

An attacker can exploit this issue to execute arbitrary script code in an=
other browser window's security zone. This may allow attackers to steal c=
ookie-based authentication credentials and launch other attacks.

NOTE: Attackers exploiting this issue on Internet Explorer 6 SP1 running =
on Microsoft Windows 2000 SP4 may leverage the issue to execute remote co=
de. Other vulnerable versions of the browser are prone only to informatio=
n disclosure.

39. Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulner=
ability
BugTraq ID: 31611
Remote: Yes
Date Published: 2008-10-07
Relevant URL: http://www.securityfocus.com/bid/31611
Summary:
Mozilla Firefox is prone to a vulnerability that allows attackers to viol=
ate the same-origin policy. This issue occurs because the application fai=
ls to properly enforce the same-origin policy when handling internet shor=
tcut files.

An attacker may create a malicious webpage that can access the properties=
 of another domain. This may allow the attacker to obtain sensitive infor=
mation or launch other attacks against a user of the browser.

Firefox 3.0.1 through 3.0.3 for Microsoft Windows are vulnerable; other v=
ersions may also be affected.

40. Microsoft Windows Active Directory LDAP Request Handling Remote Code =
Execution Vulnerability
BugTraq ID: 31609
Remote: Yes
Date Published: 2008-10-14
Relevant URL: http://www.securityfocus.com/bid/31609
Summary:
Microsoft Windows Active Directory is prone to a remote code-execution vu=
lnerability that arises because the application fails to handle specially=
 crafted LDAP or LDAP over SSL (LDAPS) requests in a proper manner.

Successfully exploiting this issue would allow an attacker to execute arb=
itrary code and gain complete access to a vulnerable computer. The attack=
er may also be able to cause the affected system to stop responding to fu=
rther requests and restart.

This issue affects only Windows 2000 servers configured as Active Directo=
ry domain controllers.

41. Internet Download Manager File Parsing Buffer Overflow Vulnerability
BugTraq ID: 31603
Remote: Yes
Date Published: 2008-10-06
Relevant URL: http://www.securityfocus.com/bid/31603
Summary:
Internet Download Manager (IDM) is prone to a remote buffer-overflow vuln=
erability because the application fails to bounds-check user-supplied dat=
a before copying it into an insufficiently sized buffer.=20

An attacker may exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

NOTE: This vulnerability may be related to the issue described in BID 141=
59 (Internet Download Manager Buffer Overflow Vulnerability), but this ha=
s not been confirmed.

We don't know which versions of IDM are affected.  We will update this BI=
D when more information emerges.

42. MetaGauge Web Server Directory Traversal Vulnerability
BugTraq ID: 31596
Remote: Yes
Date Published: 2008-10-06
Relevant URL: http://www.securityfocus.com/bid/31596
Summary:
MetaGauge is prone to a directory-traversal vulnerability because the app=
lication fails to sufficiently sanitize user-supplied input.=20

Exploiting this issue will allow an attacker to view arbitrary local file=
s within the context of the webserver. Information harvested may aid in l=
aunching further attacks.

Versions prior to MetaGauge 1.0.3.38 are vulnerable.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #415
http://www.securityfocus.com/archive/88/497234

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by HP:

Download a FREE trial of HP WebInspect
Application attacks are growing more prevalent. New attacks are in the ne=
ws each day. Now it's time for you to assess your applications and start =
detecting and removing vulnerabilities.=20
HP can help, with a full suite of application security solutions.  Get st=
arted today with a complimentary trial download that uses an HP test appl=
ication. Thoroughly analyze today's complex web applications in a runtime=
 environment with fast scanning capabilities, broad assessment coverage a=
nd accurate web application scanning results.=20
Download WebInspect now:=20

https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=3DdownloadBinSta=
rt&zn=3Dbto&cp=3D54_4012_100__&caid=3D14563&jumpid=3Dex_r11374_us/en/larg=
e/tsg/WebInspect_Eval_Secutiy_Focus/3-1QN6MII_3-UTM2ZJ/20081015&origin_id=
=3D3-1QN6MII