SecurityFocus Microsoft Newsletter #418
[email protected] 30 Oct 2008 15:36:02 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #418
----------------------------------------
This issue is sponsored by HP:
Download a FREE trial of HP WebInspect
Application attacks are growing more prevalent. New attacks are in the ne=
ws each day.=20
Now it's time for you to assess your applications and start detecting and=
removing vulnerabilities.=20
HP can help, with a full suite of application security solutions. Get sta=
rted today with a complimentary trial download that uses an HP test appli=
cation. Thoroughly analyze today's complex web applications in a runtime =
environment with fast scanning capabilities, broad assessment coverage an=
d accurate web application scanning results.=20
https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=3DdownloadBinSta=
rt&zn=3Dbto&cp=3D54_4012_100__&caid=3D14563&jumpid=3Dex_r11374_us/en/larg=
e/tsg/WebInspect_Eval_Secutiy_Focus/3-1QN6MII_3-UTM2ZJ/20081015&origin_id=
=3D3-1QN6MII=20
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Clicking to the Past
2. The Vice of Vice Presidential E-Mail
II. MICROSOFT VULNERABILITY SUMMARY
1. Microsoft Internet Explorer '&NBSP;' Address Bar URI Spoofing V=
ulnerability
2. PumpKIN Mode Field Remote Denial of Service Vulnerability
3. TUGZip ZIP File Remote Buffer Overflow Vulnerability
4. SilverSHielD 'opendir()' Remote Denial of Service Vulnerability
5. Microsoft Windows Server Service RPC Handling Remote Code Execu=
tion Vulnerability
6. freeSSHd SFTP 'rename' Remote Buffer Overflow Vulnerability
7. Multiple EMC NetWorker Products 'nsrexecd.exe' RPC Request Deni=
al of Service Vulnerability
8. Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass V=
ulnerability
9. IBM DB2 Universal Database Prior to 9.1 Fixpak 6 Multiple Vulne=
rabilities
10. Multiple Vendor Web Browser FTP Client Cross Site Scripting We=
akness
11. Wireshark 1.0.3 Multiple Denial Of Service Vulnerabilities
12. Symantec Altiris Deployment Solution Client User Interface Loc=
al Privilege Escalation Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #417
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Clicking to the Past
By Chris Wysopal
When the first details trickled out about a new attack, dubbed .clickjack=
ing. by the researchers who found it, the descriptions made me think of t=
he tricks I used to pull during penetration tests ten years ago to get ad=
ministrator privileges: Tricking the user into issuing a command on an at=
tacker.s behalf is one of the oldest attack vectors in the book.=20
http://www.securityfocus.com/columnists/483
2a .The Vice of Vice Presidential E-Mail
By Mark Rasch
Is it a crime to read someone else's e-mail without their consent? Seems =
like a simple question, but the law is not so clear. In mid-September 200=
8, a hacker using the handle "Rubico" claim credit for breaking into the =
Yahoo! e-mail account of Governor Sarah Palin, the Republican Vice Presid=
ential candidate. In a post online, Rubico wrote that he had been followi=
ng news reports that claimed Palin had been using her personal Yahoo e-ma=
il account for official government business.
In the early 90's, I attended an academic conference in Hawaii. At one pr=
esentation, a colleague from the University of California at Berkeley who=
m I'll refer to as "the supervisor," told a story of young hackers, who h=
e referred to as the Urchins
http://www.securityfocus.com/columnists/482
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Microsoft Internet Explorer '&NBSP;' Address Bar URI Spoofing Vulnerab=
ility
BugTraq ID: 31960
Remote: Yes
Date Published: 2008-10-27
Relevant URL: http://www.securityfocus.com/bid/31960
Summary:
Internet Explorer is affected by a URI-spoofing vulnerability because it =
fails to adequately handle specific combinations of the non-breaking spac=
e character ('&NBSP;').
=20
An attacker may leverage this issue to spoof the source URI of a site pre=
sented to an unsuspecting user. This may lead to a false sense of trust b=
ecause the user may be presented with a source URI of a trusted site whil=
e interacting with the attacker's malicious site.
Internet Explorer 6 is affected by this issue.
2. PumpKIN Mode Field Remote Denial of Service Vulnerability
BugTraq ID: 31922
Remote: Yes
Date Published: 2008-10-25
Relevant URL: http://www.securityfocus.com/bid/31922
Summary:
PumpKIN is prone to a remote denial-of-service vulnerability because the =
server fails to handle exceptional conditions.=20
Successfully exploiting this issue would cause the affected application t=
o become unresponsive, denying service to legitimate users.
The issue affects PumpKIN 2.7.2.0; other versions may also be vulnerable.
3. TUGZip ZIP File Remote Buffer Overflow Vulnerability
BugTraq ID: 31913
Remote: Yes
Date Published: 2008-10-25
Relevant URL: http://www.securityfocus.com/bid/31913
Summary:
TUGZip is prone to a remote buffer-overflow vulnerability because the app=
lication fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.
TUGZip 3.00 is vulnerable; other versions may also be affected.
4. SilverSHielD 'opendir()' Remote Denial of Service Vulnerability
BugTraq ID: 31884
Remote: Yes
Date Published: 2008-10-23
Relevant URL: http://www.securityfocus.com/bid/31884
Summary:
SilverSHielD is prone to a denial-of-service vulnerability because the ap=
plication fails to handle excessive user input.
An attacker may exploit this issue to crash the vulnerable application, r=
esulting in a denial-of-service condition.
SilverSHielD 1.0.2.34 is vulnerable; other versions may also be affected=
.
5. Microsoft Windows Server Service RPC Handling Remote Code Execution Vu=
lnerability
BugTraq ID: 31874
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31874
Summary:
Microsoft Windows is prone to a remote-code execution vulnerability that =
affects RPC (Remote Procedure Call) handling in the Server service.
An attacker could exploit this issue to execute arbitrary code with SYSTE=
M-level privileges. Successful exploits will result in the complete compr=
omise of vulnerable computers. This issue may be prone to widespread aut=
omated exploits. Attackers require authenticated access on Windows Vista=
and Server 2008 platforms to exploit this issue.
This vulnerability affects Windows 2000, Windows XP, Windows Server 2003,=
Windows Vista, and Windows Server 2008.
6. freeSSHd SFTP 'rename' Remote Buffer Overflow Vulnerability
BugTraq ID: 31872
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31872
Summary:
freeSSHd is prone to a remote buffer-overflow vulnerability because the a=
pplication fails to perform adequate boundary checks on user-supplied dat=
a.=20
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.
This issue affects freeSSHd 1.2.1; other versions may also be affected.
7. Multiple EMC NetWorker Products 'nsrexecd.exe' RPC Request Denial of S=
ervice Vulnerability
BugTraq ID: 31866
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31866
Summary:
Multiple EMC NetWorker products are prone to a denial-of-service vulnerab=
ility.
Attackers can exploit this issue by sending malicious RPC requests, causi=
ng affected applications to consume resources until they become unrespons=
ive. Repeated requests can lead to a denial-of-service condition.
8. Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerab=
ility
BugTraq ID: 31864
Remote: Yes
Date Published: 2008-10-22
Relevant URL: http://www.securityfocus.com/bid/31864
Summary:
Cisco PIX and ASA is prone to an authentication-bypass vulnerability.=20
Remote attackers can exploit this issue to gain unauthorized access to th=
e affected devices. Successfully exploiting this issue will lead to other=
attacks.=20
This issue is being monitored by Cisco Bug ID CSCsj25896.
9. IBM DB2 Universal Database Prior to 9.1 Fixpak 6 Multiple Vulnerabilit=
ies
BugTraq ID: 31856
Remote: Yes
Date Published: 2008-10-21
Relevant URL: http://www.securityfocus.com/bid/31856
Summary:
IBM DB2 Universal Database is prone to multiple vulnerabilities.
Successful exploits may allow attackers to obtain sensitive information o=
r cause a denial-of-service condition.
Versions prior to DB2 9.1 Fixpak 6 are affected.
10. Multiple Vendor Web Browser FTP Client Cross Site Scripting Weakness
BugTraq ID: 31855
Remote: Yes
Date Published: 2008-10-21
Relevant URL: http://www.securityfocus.com/bid/31855
Summary:
Multiple vendors' web browsers are prone a cross-site scripting weakness =
that arises because the software fails to handle specially crafted files =
served using the FTP protocol.
Successfully exploiting this issue may allow an attacker to execute arbit=
rary script code in the browser of an unsuspecting user in the context of=
an FTP session. This may allow the attacker to perform malicious actions=
in a user's browser or redirect the user to a malicious site; other atta=
cks are also possible.
11. Wireshark 1.0.3 Multiple Denial Of Service Vulnerabilities
BugTraq ID: 31838
Remote: Yes
Date Published: 2008-10-20
Relevant URL: http://www.securityfocus.com/bid/31838
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issue may allow attackers to crash the application or ca=
use the application to crash, denying service to legitimate users. Attack=
ers may be able to leverage some of these vulnerabilities to execute arbi=
trary code, but this has not been confirmed.
These issues affect Wireshark 0.10.3 up to and including 1.0.3.
12. Symantec Altiris Deployment Solution Client User Interface Local Priv=
ilege Escalation Vulnerability
BugTraq ID: 31766
Remote: No
Date Published: 2008-10-20
Relevant URL: http://www.securityfocus.com/bid/31766
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.
An attacker can exploit this issue to bypass security settings and gain p=
rivileged access. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #417
http://www.securityfocus.com/archive/88/497792
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by HP:
Download a FREE trial of HP WebInspect
Application attacks are growing more prevalent. New attacks are in the ne=
ws each day.=20
Now it's time for you to assess your applications and start detecting and=
removing vulnerabilities.=20
HP can help, with a full suite of application security solutions. Get sta=
rted today with a complimentary trial download that uses an HP test appli=
cation. Thoroughly analyze today's complex web applications in a runtime =
environment with fast scanning capabilities, broad assessment coverage an=
d accurate web application scanning results.=20
https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=3DdownloadBinSta=
rt&zn=3Dbto&cp=3D54_4012_100__&caid=3D14563&jumpid=3Dex_r11374_us/en/larg=
e/tsg/WebInspect_Eval_Secutiy_Focus/3-1QN6MII_3-UTM2ZJ/20081015&origin_id=
=3D3-1QN6MII=20