SecurityFocus Microsoft Newsletter #421
[email protected] 26 Nov 2008 17:39:29 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #421
----------------------------------------
This issue is Sponsored by Absolute Software
Securing Laptops in the Field . Live Webinar
Minimize laptop theft and data loss by managing laptops outside the netwo=
rk. In this Dec. 9 webinar, IT asset management specialist at Farmers Ins=
urance explains how he remotely audits end-user hardware and wipes out da=
ta on lost or stolen computers.
http://www.absolute.com/public/landing/CIO1208/default.asp?ref=3DSF1108-C=
IOwebinar
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Just Encase It's Not a Search
2.Microsoft's Stance on Piracy Affects Us All
II. MICROSOFT VULNERABILITY SUMMARY
1. Nero ShowTime '.m3u' File Remote Buffer Overflow Vulnerability
2. Wireshark 1.0.4 SMTP Denial of Service Vulnerability
3. BitDefender 'pdf.xmd' Module PDF Parsing Remote Denial Of Servi=
ce Vulnerability
4. Microsoft Windows Vista 'iphlpapi.dll' Local Kernel Buffer Over=
flow Vulnerability
5. Symantec Backup Exec for Windows Server Remote Agent Authentica=
tion Bypass Vulnerability
6. Symantec Backup Exec Data Management Protocol Buffer Overflow V=
ulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #420
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Just Encase It's Not a Search
By Mark Rasch
When is a search not really a search? If it.s done by computer, according=
to U.S. government lawyers.=20
http://www.securityfocus.com/columnists/485
2.Microsoft's Stance on Piracy Affects Us All
By Oliver Day
For the last few years, Microsoft has wrestled with their stance on pirac=
y. Pirated operating systems are just like legitimate operating systems i=
n terms of their exposure to vulnerabilities: Users must install patches =
or they will be compromised.
http://www.securityfocus.com/columnists/484
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Nero ShowTime '.m3u' File Remote Buffer Overflow Vulnerability
BugTraq ID: 32446
Remote: Yes
Date Published: 2008-11-24
Relevant URL: http://www.securityfocus.com/bid/32446
Summary:
Nero ShowTime is prone to a remote buffer-overflow vulnerability because =
the application fails to perform adequate boundary checks on user-supplie=
d input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
NOTE: This issue may be related to BID 27615 (Nero Media Player M3U Buffe=
r Overflow Vulnerability), but this has not been confirmed.
ShowTime 5.0.15.0 is vulnerable; other versions may also be affected.
2. Wireshark 1.0.4 SMTP Denial of Service Vulnerability
BugTraq ID: 32422
Remote: Yes
Date Published: 2008-11-22
Relevant URL: http://www.securityfocus.com/bid/32422
Summary:
Wireshark is prone to a denial-of-service vulnerability.
Exploiting this issue may allow attackers to cause the application to han=
g, which may aid in other attacks.
This issue affects Wireshark 1.0.4; other versions may also be vulnerable=
.
3. BitDefender 'pdf.xmd' Module PDF Parsing Remote Denial Of Service Vuln=
erability
BugTraq ID: 32396
Remote: Yes
Date Published: 2008-11-20
Relevant URL: http://www.securityfocus.com/bid/32396
Summary:
BitDefender is prone to a remote denial-of-service vulnerability that occ=
urs when a malicious PDF file is scanned using BitDefender's command-line=
scanner 'bdc.exe'. =20
Attackers can exploit this issue to deny service to legitimate users.
UPDATE (November 25, 2008): Further reports indicate that the vulnerable =
module 'pdf.xmd' is used in other applications, rendering them vulnerable=
as well.
4. Microsoft Windows Vista 'iphlpapi.dll' Local Kernel Buffer Overflow Vu=
lnerability
BugTraq ID: 32357
Remote: No
Date Published: 2008-11-19
Relevant URL: http://www.securityfocus.com/bid/32357
Summary:
Microsoft Windows Vista is prone to a buffer-overflow vulnerability beca=
use of insufficient boundary checks.
Local attackers could exploit this issue to cause denial-of-service condi=
tions. Given the nature of this issue, attackers may also be able to exec=
ute arbitrary code with SYSTEM-level privileges, but this has not been co=
nfirmed.
Windows Vista SP1 is vulnerable to this issue.
UPDATE (November 25, 2008): Since this issue may be exploitable only by m=
embers of the administrative group, the security implication of this issu=
e may be negated.
5. Symantec Backup Exec for Windows Server Remote Agent Authentication By=
pass Vulnerability
BugTraq ID: 32347
Remote: Yes
Date Published: 2008-11-19
Relevant URL: http://www.securityfocus.com/bid/32347
Summary:
Symantec Backup Exec for Windows Server is prone to a vulnerability that =
allows an attacker to bypass authentication and gain unauthorized access =
to the affected application.=20
=20
Attackers with authorized network access can exploit this issue to bypas=
s the logon process using the remote agents. Successfully exploits may al=
low attackers to retrieve or delete files on the targeted computer.
6. Symantec Backup Exec Data Management Protocol Buffer Overflow Vulnerab=
ility
BugTraq ID: 32346
Remote: Yes
Date Published: 2008-11-19
Relevant URL: http://www.securityfocus.com/bid/32346
Summary:
Symantec Backup Exec is prone to a buffer-overflow vulnerability because =
the application fails to perform adequate boundary checks on user-supplie=
d data.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application. Failed exploit attempts wi=
ll likely result in denial-of-service conditions.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #420
http://www.securityfocus.com/archive/88/498546
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by Absolute Software
Securing Laptops in the Field . Live Webinar
Minimize laptop theft and data loss by managing laptops outside the netwo=
rk. In this Dec. 9 webinar, IT asset management specialist at Farmers Ins=
urance explains how he remotely audits end-user hardware and wipes out da=
ta on lost or stolen computers.
http://www.absolute.com/public/landing/CIO1208/default.asp?ref=3DSF1108-C=
IOwebinar