SecurityFocus Microsoft Newsletter #432

[email protected] Thu, 19 Feb 2009 16:40:45 -0700
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #432
----------------------------------------

This issue is sponsored by Purewire

NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.
=20
http://www.purewire.com/lp/sec/


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Free Market Filtering
       2. Don't Blame the Browser
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Got All Media URI Handling Remote Denial of Service Vulnerabili=
ty
       2. Agavi Multiple Cross Site Scripting Vulnerabilities
       3. Windows Live Messenger Charset Data Remote Denial Of Service Vu=
lnerability
       4. Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header =
Information Disclosure Vulnerability
       5. RimArts Becky! Internet Mail Return Receipt Remote Buffer Overf=
low Vulnerability
       6. Wireshark 1.0.5 Multiple Denial Of Service Vulnerabilities
       7. Microsoft Visio Memory Corruption Remote Code Execution Vulnera=
bility
       8. Microsoft Visio Object Copy Memory Corruption Remote Code Execu=
tion Vulnerability
       9. Microsoft Visio Object Validation Remote Code Execution Vulnera=
bility
       10. Microsoft Internet Explorer CSS Memory Corruption Remote Code =
Execution Vulnerability
       11. Microsoft Internet Explorer Uninitialized Memory Remote Code E=
xecution Vulnerability
       12. Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial o=
f Service Vulnerability
       13. Microsoft Exchange Server TNEF Decoding Remote Code Execution =
Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Free Market Filtering
By Mark Rasch
The Australian government is considering requiring that Internet service =
providers in that country install filters which would prevent citizens fr=
om accessing tens of thousands of sites that contain "objectionable" mate=
rial.=20
http://www.securityfocus.com/columnists/493

2.Don't Blame the Browser
Melih Abdulhayoglu
There was a time when most diseases were fatal for humans. Intense study =
and research helped doctors manage diseases better, and subsequently even=
 prevent them altogether.=20
http://www.securityfocus.com/columnists/492


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Got All Media URI Handling Remote Denial of Service Vulnerability
BugTraq ID: 33830
Remote: Yes
Date Published: 2009-02-19
Relevant URL: http://www.securityfocus.com/bid/33830
Summary:
Got All Media is prone to a remote denial-of-service vulnerability when p=
rocessing URI requests.
=20
Exploiting this issue allows remote attackers to cause denial-of-service =
conditions by crashing the application.

Got All Media 7.0.0.3 is vulnerable; other versions may be affected as we=
ll.

2. Agavi Multiple Cross Site Scripting Vulnerabilities
BugTraq ID: 33826
Remote: Yes
Date Published: 2009-02-18
Relevant URL: http://www.securityfocus.com/bid/33826
Summary:
Agavi is prone to multiple cross-site scripting vulnerabilities because i=
t fails to sufficiently sanitize user-supplied input.

Attacker-supplied HTML and script code would run in the context of the af=
fected site, potentially allowing the attacker to steal cookie-based auth=
entication credentials.

3. Windows Live Messenger Charset Data Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 33825
Remote: Yes
Date Published: 2009-02-18
Relevant URL: http://www.securityfocus.com/bid/33825
Summary:
Windows Live Messenger is prone to a remote denial-of-service vulnerabili=
ty.=20

An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20

Windows Live Messenger 2009 14.0.8064.206 is vulnerable; other versions m=
ay also be affected.

4. Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Informa=
tion Disclosure Vulnerability
BugTraq ID: 33803
Remote: Yes
Date Published: 2009-02-17
Relevant URL: http://www.securityfocus.com/bid/33803
Summary:
Microsoft XML Core Services (MSXML) is prone to an information-disclosure=
 vulnerability because it fails to properly protect sensitive cookie data=
 with the 'HTTPOnly' protection mechanism.

A successful exploit may allow attackers to steal cookie-based authentica=
tion credentials; information harvested may aid in further attacks.

5. RimArts Becky! Internet Mail Return Receipt Remote Buffer Overflow Vul=
nerability
BugTraq ID: 33756
Remote: Yes
Date Published: 2009-02-12
Relevant URL: http://www.securityfocus.com/bid/33756
Summary:
RimArts Becky! Internet Mail is prone to a remote buffer-overflow vulnera=
bility because the application fails to perform adequate boundary checks =
on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Versions prior to Becky! Internet Mail 2.50 are vulnerable.

6. Wireshark 1.0.5 Multiple Denial Of Service Vulnerabilities
BugTraq ID: 33690
Remote: Yes
Date Published: 2009-02-09
Relevant URL: http://www.securityfocus.com/bid/33690
Summary:
Wireshark is prone to multiple denial-of-service vulnerabilities.

Exploiting these issues may allow attackers to crash the application, den=
ying service to legitimate users. Attackers may be able to leverage some =
of these vulnerabilities to execute arbitrary code, but this has not been=
 confirmed.

These issues affect Wireshark 0.99.6 through 1.0.5.

7. Microsoft Visio Memory Corruption Remote Code Execution Vulnerability
BugTraq ID: 33661
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33661
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
 it fails to adequately handle user-supplied data.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Failed exploit attempts will result=
 in a  denial-of-service condition.

8. Microsoft Visio Object Copy Memory Corruption Remote Code Execution Vu=
lnerability
BugTraq ID: 33660
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33660
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
 it fails to adequately handle user-supplied data.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Failed exploit attempts will result=
 in a  denial-of-service condition.

9. Microsoft Visio Object Validation Remote Code Execution Vulnerability
BugTraq ID: 33659
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33659
Summary:
Microsoft Visio is prone to a remote code-execution vulnerability because=
 it fails to adequately handle user-supplied data.

Attackers can exploit this issue to run arbitrary code in the context of =
the user running the application. Failed exploit attempts will result in =
a  denial-of-service condition.

10. Microsoft Internet Explorer CSS Memory Corruption Remote Code Executi=
on Vulnerability
BugTraq ID: 33628
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33628
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

11. Microsoft Internet Explorer Uninitialized Memory Remote Code Executio=
n Vulnerability
BugTraq ID: 33627
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33627
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the underlying computer. Failed attacks wil=
l cause denial-of-service conditions.

12. Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Servi=
ce Vulnerability
BugTraq ID: 33136
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33136
Summary:
Microsoft Exchange Server is prone to a remote denial-of-service vulnerab=
ility.

A successful exploit allows a remote attacker to cause the application to=
 stop responding, denying service to legitimate users.

13. Microsoft Exchange Server TNEF Decoding Remote Code Execution Vulnera=
bility
BugTraq ID: 33134
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33134
Summary:
Microsoft Exchange Server is prone to a remote code-execution vulnerabili=
ty.=20

Remote attackers may exploit this issue by sending maliciously constructe=
d TNEF-encoded email data to vulnerable servers. This issue will be trigg=
ered when a user views or previews the malicious email.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code on an affected computer in the context of the affected appli=
cation.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Purewire

NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.
=20
http://www.purewire.com/lp/sec/