SecurityFocus Microsoft Newsletter #422

[email protected] Thu, 4 Dec 2008 23:17:05 -0700
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #422
----------------------------------------

This issue is Sponsored by Verisign

Learn how to protect your online customers with SSL technology that not o=
nly keeps their information safe, but also lets them know your site is se=
cure - Extended Validation (EV) SSL.=20
This new technology turns the address bar green in high security browsers=
.
http://ad.doubleclick.net/clk;208565397;30663982;v


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Standing on Other's Shoulders
       2. Just Encase It's Not a Search
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Microsoft December 2008 Advance Notification Multiple Vulnerabi=
lities
       2. RadASM '.rap' Project File Buffer Overflow Vulnerability
       3. Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vu=
lnerability
       4. MemeCode Software i.Scribe Remote Format String Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #421
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Standing on Other's Shoulders
By Chris Wysopal
"If I have seen a little further it is by standing on the shoulders of Gi=
ants," Issac Netwon once wrote to describe how he felt that his scientifi=
c work was an extension of the work of those who went before him. In the =
scientific realm it is dishonorable not to credit those upon whose work y=
ou build.=20
http://www.securityfocus.com/columnists/486

2.Just Encase It's Not a Search
By Mark Rasch
When is a search not really a search? If it's done by computer, according=
 to U.S. government lawyers.=20
http://www.securityfocus.com/columnists/485


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Microsoft December 2008 Advance Notification Multiple Vulnerabilities
BugTraq ID: 32632
Remote: Yes
Date Published: 2008-12-04
Relevant URL: http://www.securityfocus.com/bid/32632
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing eight security bulletins on December 9, 2008. The highest severity r=
ating for these issues is 'Critical'.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

Individual records will be created for the issues when the bulletins are =
released.

2. RadASM '.rap' Project File Buffer Overflow Vulnerability
BugTraq ID: 32617
Remote: Yes
Date Published: 2008-12-03
Relevant URL: http://www.securityfocus.com/bid/32617
Summary:
RadASM is prone to a buffer-overflow vulnerability because it fails to pe=
rform adequate checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
 RadASM 2.2.1.4 is vulnerable; other versions may also be affected.

3. Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerabi=
lity
BugTraq ID: 32540
Remote: Yes
Date Published: 2008-11-30
Relevant URL: http://www.securityfocus.com/bid/32540
Summary:
Apple iTunes and QuickTime are prone to a buffer-overflow  vulnerability =
because the applications fail to bounds-check user-supplied data before c=
opying it into an insufficiently sized buffer.=20

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.=20

This issue affects the following:

iTunes 8.0.2.20
QuickTime 7.5.5

4. MemeCode Software i.Scribe Remote Format String Vulnerability
BugTraq ID: 32497
Remote: Yes
Date Published: 2008-11-27
Relevant URL: http://www.securityfocus.com/bid/32497
Summary:
MemeCode Software i.Scribe is prone to a remote format-string vulnerabili=
ty because it fails to properly sanitize user-supplied input before passi=
ng it as the format specifier to a formatted-printing function.

An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the vulnerable application. Failed exploit attempts will likely res=
ult in a denial-of-service condition.

i.Scribe 1.88 and 2.00 beta are vulnerable; other versions may also be af=
fected.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #421
http://www.securityfocus.com/archive/88/498758

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is Sponsored by Verisign

Learn how to protect your online customers with SSL technology that not o=
nly keeps their information safe, but also lets them know your site is se=
cure - Extended Validation (EV) SSL.=20
This new technology turns the address bar green in high security browsers=
.
http://ad.doubleclick.net/clk;208565397;30663982;v