SecurityFocus Microsoft Newsletter #432
[email protected] Thu, 19 Feb 2009 16:40:45 -0700
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #432
----------------------------------------
This issue is sponsored by Purewire
NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"
Learn how hackers are exploiting your employees Web surfing to gain entry=
into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.
=20
http://www.purewire.com/lp/sec/
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Free Market Filtering
2. Don't Blame the Browser
II. MICROSOFT VULNERABILITY SUMMARY
1. Got All Media URI Handling Remote Denial of Service Vulnerabili=
ty
2. Agavi Multiple Cross Site Scripting Vulnerabilities
3. Windows Live Messenger Charset Data Remote Denial Of Service Vu=
lnerability
4. Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header =
Information Disclosure Vulnerability
5. RimArts Becky! Internet Mail Return Receipt Remote Buffer Overf=
low Vulnerability
6. Wireshark 1.0.5 Multiple Denial Of Service Vulnerabilities
7. Microsoft Visio Memory Corruption Remote Code Execution Vulnera=
bility
8. Microsoft Visio Object Copy Memory Corruption Remote Code Execu=
tion Vulnerability
9. Microsoft Visio Object Validation Remote Code Execution Vulnera=
bility
10. Microsoft Internet Explorer CSS Memory Corruption Remote Code =
Execution Vulnerability
11. Microsoft Internet Explorer Uninitialized Memory Remote Code E=
xecution Vulnerability
12. Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial o=
f Service Vulnerability
13. Microsoft Exchange Server TNEF Decoding Remote Code Execution =
Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Free Market Filtering
By Mark Rasch
The Australian government is considering requiring that Internet service =
providers in that country install filters which would prevent citizens fr=
om accessing tens of thousands of sites that contain "objectionable" mate=
rial.=20
http://www.securityfocus.com/columnists/493
2.Don't Blame the Browser
Melih Abdulhayoglu
There was a time when most diseases were fatal for humans. Intense study =
and research helped doctors manage diseases better, and subsequently even=
prevent them altogether.=20
http://www.securityfocus.com/columnists/492
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Got All Media URI Handling Remote Denial of Service Vulnerability
BugTraq ID: 33830
Remote: Yes
Date Published: 2009-02-19
Relevant URL: http://www.securityfocus.com/bid/33830
Summary:
Got All Media is prone to a remote denial-of-service vulnerability when p=
rocessing URI requests.
=20
Exploiting this issue allows remote attackers to cause denial-of-service =
conditions by crashing the application.
Got All Media 7.0.0.3 is vulnerable; other versions may be affected as we=
ll.
2. Agavi Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 33826
Remote: Yes
Date Published: 2009-02-18
Relevant URL: http://www.securityfocus.com/bid/33826
Summary:
Agavi is prone to multiple cross-site scripting vulnerabilities because i=
t fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the af=
fected site, potentially allowing the attacker to steal cookie-based auth=
entication credentials.
3. Windows Live Messenger Charset Data Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 33825
Remote: Yes
Date Published: 2009-02-18
Relevant URL: http://www.securityfocus.com/bid/33825
Summary:
Windows Live Messenger is prone to a remote denial-of-service vulnerabili=
ty.=20
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20
Windows Live Messenger 2009 14.0.8064.206 is vulnerable; other versions m=
ay also be affected.
4. Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Informa=
tion Disclosure Vulnerability
BugTraq ID: 33803
Remote: Yes
Date Published: 2009-02-17
Relevant URL: http://www.securityfocus.com/bid/33803
Summary:
Microsoft XML Core Services (MSXML) is prone to an information-disclosure=
vulnerability because it fails to properly protect sensitive cookie data=
with the 'HTTPOnly' protection mechanism.
A successful exploit may allow attackers to steal cookie-based authentica=
tion credentials; information harvested may aid in further attacks.
5. RimArts Becky! Internet Mail Return Receipt Remote Buffer Overflow Vul=
nerability
BugTraq ID: 33756
Remote: Yes
Date Published: 2009-02-12
Relevant URL: http://www.securityfocus.com/bid/33756
Summary:
RimArts Becky! Internet Mail is prone to a remote buffer-overflow vulnera=
bility because the application fails to perform adequate boundary checks =
on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
Versions prior to Becky! Internet Mail 2.50 are vulnerable.
6. Wireshark 1.0.5 Multiple Denial Of Service Vulnerabilities
BugTraq ID: 33690
Remote: Yes
Date Published: 2009-02-09
Relevant URL: http://www.securityfocus.com/bid/33690
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may allow attackers to crash the application, den=
ying service to legitimate users. Attackers may be able to leverage some =
of these vulnerabilities to execute arbitrary code, but this has not been=
confirmed.
These issues affect Wireshark 0.99.6 through 1.0.5.
7. Microsoft Visio Memory Corruption Remote Code Execution Vulnerability
BugTraq ID: 33661
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33661
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
it fails to adequately handle user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context=
of the user running the application. Failed exploit attempts will result=
in a denial-of-service condition.
8. Microsoft Visio Object Copy Memory Corruption Remote Code Execution Vu=
lnerability
BugTraq ID: 33660
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33660
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
it fails to adequately handle user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context=
of the user running the application. Failed exploit attempts will result=
in a denial-of-service condition.
9. Microsoft Visio Object Validation Remote Code Execution Vulnerability
BugTraq ID: 33659
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33659
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
it fails to adequately handle user-supplied data.
Attackers can exploit this issue to run arbitrary code in the context of =
the user running the application. Failed exploit attempts will result in =
a denial-of-service condition.
10. Microsoft Internet Explorer CSS Memory Corruption Remote Code Executi=
on Vulnerability
BugTraq ID: 33628
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33628
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.
Attackers can exploit this issue to execute arbitrary code in the context=
of the user running the application. Successful exploits will compromise=
the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.
11. Microsoft Internet Explorer Uninitialized Memory Remote Code Executio=
n Vulnerability
BugTraq ID: 33627
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33627
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.
Attackers can exploit this issue to execute arbitrary code in the context=
of the user running the application. Successful exploits will compromise=
the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.
12. Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Servi=
ce Vulnerability
BugTraq ID: 33136
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33136
Summary:
Microsoft Exchange Server is prone to a remote denial-of-service vulnerab=
ility.
A successful exploit allows a remote attacker to cause the application to=
stop responding, denying service to legitimate users.
13. Microsoft Exchange Server TNEF Decoding Remote Code Execution Vulnera=
bility
BugTraq ID: 33134
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33134
Summary:
Microsoft Exchange Server is prone to a remote code-execution vulnerabili=
ty.=20
Remote attackers may exploit this issue by sending maliciously constructe=
d TNEF-encoded email data to vulnerable servers. This issue will be trigg=
ered when a user views or previews the malicious email.
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code on an affected computer in the context of the affected appli=
cation.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Purewire
NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"
Learn how hackers are exploiting your employees Web surfing to gain entry=
into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.
=20
http://www.purewire.com/lp/sec/