SecurityFocus Microsoft Newsletter #422
[email protected] Thu, 4 Dec 2008 23:17:05 -0700
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #422
----------------------------------------
This issue is Sponsored by Verisign
Learn how to protect your online customers with SSL technology that not o=
nly keeps their information safe, but also lets them know your site is se=
cure - Extended Validation (EV) SSL.=20
This new technology turns the address bar green in high security browsers=
.
http://ad.doubleclick.net/clk;208565397;30663982;v
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Standing on Other's Shoulders
2. Just Encase It's Not a Search
II. MICROSOFT VULNERABILITY SUMMARY
1. Microsoft December 2008 Advance Notification Multiple Vulnerabi=
lities
2. RadASM '.rap' Project File Buffer Overflow Vulnerability
3. Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vu=
lnerability
4. MemeCode Software i.Scribe Remote Format String Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. SecurityFocus Microsoft Newsletter #421
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Standing on Other's Shoulders
By Chris Wysopal
"If I have seen a little further it is by standing on the shoulders of Gi=
ants," Issac Netwon once wrote to describe how he felt that his scientifi=
c work was an extension of the work of those who went before him. In the =
scientific realm it is dishonorable not to credit those upon whose work y=
ou build.=20
http://www.securityfocus.com/columnists/486
2.Just Encase It's Not a Search
By Mark Rasch
When is a search not really a search? If it's done by computer, according=
to U.S. government lawyers.=20
http://www.securityfocus.com/columnists/485
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Microsoft December 2008 Advance Notification Multiple Vulnerabilities
BugTraq ID: 32632
Remote: Yes
Date Published: 2008-12-04
Relevant URL: http://www.securityfocus.com/bid/32632
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing eight security bulletins on December 9, 2008. The highest severity r=
ating for these issues is 'Critical'.
Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.
Individual records will be created for the issues when the bulletins are =
released.
2. RadASM '.rap' Project File Buffer Overflow Vulnerability
BugTraq ID: 32617
Remote: Yes
Date Published: 2008-12-03
Relevant URL: http://www.securityfocus.com/bid/32617
Summary:
RadASM is prone to a buffer-overflow vulnerability because it fails to pe=
rform adequate checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
RadASM 2.2.1.4 is vulnerable; other versions may also be affected.
3. Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerabi=
lity
BugTraq ID: 32540
Remote: Yes
Date Published: 2008-11-30
Relevant URL: http://www.securityfocus.com/bid/32540
Summary:
Apple iTunes and QuickTime are prone to a buffer-overflow vulnerability =
because the applications fail to bounds-check user-supplied data before c=
opying it into an insufficiently sized buffer.=20
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.=20
This issue affects the following:
iTunes 8.0.2.20
QuickTime 7.5.5
4. MemeCode Software i.Scribe Remote Format String Vulnerability
BugTraq ID: 32497
Remote: Yes
Date Published: 2008-11-27
Relevant URL: http://www.securityfocus.com/bid/32497
Summary:
MemeCode Software i.Scribe is prone to a remote format-string vulnerabili=
ty because it fails to properly sanitize user-supplied input before passi=
ng it as the format specifier to a formatted-printing function.
An attacker may exploit this issue to execute arbitrary code in the conte=
xt of the vulnerable application. Failed exploit attempts will likely res=
ult in a denial-of-service condition.
i.Scribe 1.88 and 2.00 beta are vulnerable; other versions may also be af=
fected.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #421
http://www.securityfocus.com/archive/88/498758
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is Sponsored by Verisign
Learn how to protect your online customers with SSL technology that not o=
nly keeps their information safe, but also lets them know your site is se=
cure - Extended Validation (EV) SSL.=20
This new technology turns the address bar green in high security browsers=
.
http://ad.doubleclick.net/clk;208565397;30663982;v