SecurityFocus Microsoft Newsletter #435
[email protected] Wed, 11 Mar 2009 15:40:29 -0700
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #435
----------------------------------------
This issue is sponsored by Sophos
Laws, regulations and compliance: Top tips for keeping your data under yo=
ur control=20
=20
http://dinclinx.com/Redirect.aspx?36;4035;35;189;0;5;259;787c0986ab9c445a
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Contracting For Secure Code
2. Free Market Filtering
II. MICROSOFT VULNERABILITY SUMMARY
1. PostgreSQL Conversion Encoding Remote Denial of Service Vulnera=
bility
2. RainbowPlayer '.rpl' File Remote Buffer Overflow Vulnerability
3. PostgreSQL Low Cost Function Information Disclosure Vulnerabili=
ty
4. MediaCoder '.m3u' File Remote Stack Buffer Overflow Vulnerabili=
ty
5. eZip Wizard Zip File Stack Remote Buffer Overflow Vulnerability
6. RadASM '.rap' Project File Stack-Based Buffer Overflow Vulnerab=
ility
7. Nokia Multimedia Player '.npl' File Heap Buffer Overflow Vulner=
ability
8. mks_vir 'mksmonen.sys' IOCTL Request Local Privilege Escalation=
Vulnerability
9. Microsoft Windows Kernel Handle Local Privilege Escalation Vuln=
erability
10. Microsoft Windows Invalid Pointer Local Privilege Escalation V=
ulnerability
11. Microsoft Windows SChannel Authentication Spoofing Vulnerabili=
ty
12. Microsoft Windows WINS Server WPAD and ISATAP Access Validatio=
n Vulnerability
13. Microsoft Windows Kernel GDI EMF/WMF Remote Code Execution Vul=
nerability
14. Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerabi=
lity
15. Multiple Vendor libc 'fts.c' Denial of Service Vulnerability
16. FileZilla Server SSL/TLS Unspecified Buffer Overflow Denial Of=
Service Vulnerability
17. Microsoft March 2009 Advance Notification Multiple Vulnerabili=
ties
18. Microsoft Windows DNS Server WPAD Access Validation Vulnerabil=
ity
19. Microsoft Windows DNS Server Incorrect Caching DNS Spoofing Vu=
lnerability
20. Microsoft Windows DNS Server Response Caching DNS Spoofing Vul=
nerability
21. Easy File Sharing Web Server 'thumbnail.php' File Disclosure V=
ulnerability
22. EFS Software Easy Chat Server 'registresult.htm' Authenticatio=
n Bypass Vulnerability
23. VUPlayer '.CUE' File Buffer Overflow Vulnerability
24. Media Commands Multiple Media File Multiple Heap Buffer Overfl=
ow Vulnerabilities
III. MICROSOFT FOCUS LIST SUMMARY
1. SQL Server stored procedure encryption
2. SecurityFocus Microsoft Newsletter #434
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Contracting For Secure Code
By Chris Wysopal
Forcing suppliers to attest to the security of provided software is gaini=
ng adherents: Just ask Kaspersky Lab.=20
http://www.securityfocus.com/columnists/494
2. Free Market Filtering
By Mark Rasch
The Australian government is considering requiring that Internet service =
providers in that country install filters which would prevent citizens fr=
om accessing tens of thousands of sites that contain "objectionable" mate=
rial.=20
http://www.securityfocus.com/columnists/493
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
BugTraq ID: 34090
Remote: Yes
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34090
Summary:
PostgreSQL is prone to a remote denial-of-service vulnerability.
Exploiting this issue may allow attackers to terminate connections to the=
PostgreSQL server, denying service to legitimate users.
2. RainbowPlayer '.rpl' File Remote Buffer Overflow Vulnerability
BugTraq ID: 34072
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34072
Summary:
RainbowPlayer is prone to a remote buffer-overflow vulnerability because =
the application fails to perform adequate boundary checks on user-supplie=
d input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
RainbowPlayer 0.91 is vulnerable; other versions may also be affected.
3. PostgreSQL Low Cost Function Information Disclosure Vulnerability
BugTraq ID: 34069
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34069
Summary:
PostgreSQL is prone to an information-disclosure vulnerability.=20
Local attackers can exploit this issue to gain access to sensitive inform=
ation. Information obtained may lead to further attacks.=20
PostgreSQL 8.3.6 is vulnerable; other versions may also be affected.
4. MediaCoder '.m3u' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 34051
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34051
Summary:
MediaCoder is prone to a remote stack-based buffer-overflow vulnerability=
because the application fails to perform adequate boundary checks on use=
r-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
MediaCoder 6.2.4275 is vulnerable; other versions may also be affected.
5. eZip Wizard Zip File Stack Remote Buffer Overflow Vulnerability
BugTraq ID: 34044
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34044
Summary:
eZip Wizard is prone to a remote stack-based buffer-overflow vulnerabilit=
y because the application fails to perform adequate boundary checks on us=
er-supplied data.
An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.
eZip Wizard 3.0 is vulnerable; other versions may also be affected.
6. RadASM '.rap' Project File Stack-Based Buffer Overflow Vulnerability
BugTraq ID: 34042
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34042
Summary:
RadASM is prone to a stack-based buffer-overflow vulnerability because it=
fails to perform adequate checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
RadASM 2.2.1.5 is vulnerable; other versions may also be affected.
7. Nokia Multimedia Player '.npl' File Heap Buffer Overflow Vulnerability
BugTraq ID: 34041
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34041
Summary:
Nokia Multimedia Player is prone to a heap-based buffer-overflow vulnerab=
ility because it fails to perform adequate boundary checks on user-suppli=
ed input.
Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of the application. Failed exploit attempt=
s will cause denial-of-service conditions.
Nokia Multimedia Player 1.0 is vulnerable; other versions may also be aff=
ected.
8. mks_vir 'mksmonen.sys' IOCTL Request Local Privilege Escalation Vulner=
ability
BugTraq ID: 34039
Remote: No
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34039
Summary:
The 'mks_vir' program is prone a local privilege-escalation vulnerability=
.
An attacker can exploit this issue to execute arbitrary code with elevate=
d privileges; this may aid in further attacks.
Versions prior to mks_vir 9 Beta 1.2.0.0 build 297 are vulnerable.
9. Microsoft Windows Kernel Handle Local Privilege Escalation Vulnerabili=
ty
BugTraq ID: 34027
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34027
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.
An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.
10. Microsoft Windows Invalid Pointer Local Privilege Escalation Vulnerab=
ility
BugTraq ID: 34025
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34025
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.
An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.
11. Microsoft Windows SChannel Authentication Spoofing Vulnerability
BugTraq ID: 34015
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34015
Summary:
Microsoft Windows SChannel is prone to an authentication-spoofing vulnera=
bility because it fails to properly validate certain client-server certif=
icate exchanges.
Successful exploits will allow attackers to authenticate to trusted serve=
rs by spoofing a legitimate user's credentials. This may aid in further a=
ttacks.
12. Microsoft Windows WINS Server WPAD and ISATAP Access Validation Vulne=
rability
BugTraq ID: 34013
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34013
Summary:
The Microsoft Windows WINS Server is prone to an access-validation vulner=
ability because the software fails to properly restrict access when defin=
ing WPAD (Web Proxy Autodiscovery Protocol) and ISATAP (Intra-Site Automa=
tic Tunnel Addressing Protocol) entries.
An authenticated attacker may exploit this issue to create a WPAD or ISAT=
AP WINS entry. This may aid in man-in-the-middle and spoofing attacks. Ot=
her attacks are also possible.
13. Microsoft Windows Kernel GDI EMF/WMF Remote Code Execution Vulnerabil=
ity
BugTraq ID: 34012
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34012
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to =
open a malicious EMF or WMF image file.=20
Successfully exploiting this issue will allow attackers to execute arbitr=
ary code with kernel-level privileges, completely compromising affected c=
omputers. Failed exploit attempts will result in a denial-of-service cond=
ition.
14. Nullsoft Winamp 'skin.xml' Skin File Buffer Overflow Vulnerability
BugTraq ID: 34009
Remote: Yes
Date Published: 2009-03-05
Relevant URL: http://www.securityfocus.com/bid/34009
Summary:
Nullsoft Winamp is prone to a buffer-overflow vulnerability because the a=
pplication fails to perform adequate boundary checks on user-supplied inp=
ut.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
Note that this issue may be related to BID 5832 (Nullsoft Winamp 3 Skin F=
ile Buffer Overflow Vulnerability).
Versions prior to Winamp 5.55 are vulnerable.
15. Multiple Vendor libc 'fts.c' Denial of Service Vulnerability
BugTraq ID: 34008
Remote: No
Date Published: 2009-03-05
Relevant URL: http://www.securityfocus.com/bid/34008
Summary:
Multiple libc libraries are prone to a denial-of-service vulnerability ca=
used by an error when handling deeply nested directory structures.
An attacker can exploit this issue to cause applications using vulnerable=
libraries to crash with a segmentation fault, denying service to legitim=
ate users.
=20
The following are reported vulnerable:
OpenBSD 4.4
Microsoft Interix 6.0 10.0.6030.0
Microsoft Vista Enterprise
Other libraries may also be affected.
16. FileZilla Server SSL/TLS Unspecified Buffer Overflow Denial Of Servic=
e Vulnerability
BugTraq ID: 34006
Remote: Yes
Date Published: 2009-03-05
Relevant URL: http://www.securityfocus.com/bid/34006
Summary:
FileZilla Server is prone to a denial-of-service vulnerability because it=
fails to adequately validate data before copying it into an insufficient=
ly sized buffer.
Attackers can exploit this issue to cause denial-of-service conditions. G=
iven the nature of this issue, remote code execution may also be possible=
, but this has not been confirmed.
Versions prior to FileZilla Server 0.9.31 are vulnerable.
17. Microsoft March 2009 Advance Notification Multiple Vulnerabilities
BugTraq ID: 34005
Remote: Yes
Date Published: 2009-03-05
Relevant URL: http://www.securityfocus.com/bid/34005
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing three security bulletins on March 10, 2009. The highest severity rat=
ing for these issues is 'Critical'.
These issues affect Windows.
Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.
Individual records will be created to better document these issues when t=
he bulletins are released.
18. Microsoft Windows DNS Server WPAD Access Validation Vulnerability
BugTraq ID: 33989
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/33989
Summary:
The Microsoft Windows DNS Server is prone to an access-validation vulnera=
bility because the software fails to properly restrict access when defini=
ng WPAD (Web Proxy Autodiscovery Protocol) entries.
An authenticated attacker may exploit this issue to create a WPAD DNS ent=
ry. This may aid in man-in-the-middle and spoofing attacks. Other attacks=
are also possible.
19. Microsoft Windows DNS Server Incorrect Caching DNS Spoofing Vulnerabi=
lity
BugTraq ID: 33988
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/33988
Summary:
The Microsoft Windows DNS Server is prone to a DNS-spoofing vulnerability=
because the software fails to cache responses to specially crafted DNS q=
ueries.
=20
Successfully exploiting this issue allows remote attackers to spoof DNS r=
eplies, allowing them to redirect network traffic and to launch man-in-th=
e-middle attacks.
20. Microsoft Windows DNS Server Response Caching DNS Spoofing Vulnerabil=
ity
BugTraq ID: 33982
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/33982
Summary:
The Microsoft Windows DNS Server is prone to a DNS-spoofing vulnerability=
because the software fails to properly reuse cached responses.
=20
Successfully exploiting this issue allows remote attackers to spoof DNS r=
eplies, allowing them to redirect network traffic and to launch man-in-th=
e-middle attacks.
21. Easy File Sharing Web Server 'thumbnail.php' File Disclosure Vulnerab=
ility
BugTraq ID: 33973
Remote: Yes
Date Published: 2009-03-04
Relevant URL: http://www.securityfocus.com/bid/33973
Summary:
Easy File Sharing Web Server is prone to a vulnerability that lets attac=
kers obtain potentially sensitive information because it fails to properl=
y sanitize user-supplied input.
An attacker can exploit this issue to download arbitrary files with the p=
rivileges of the webserver process. Information obtained may aid in furth=
er attacks.
Easy File Sharing Web Server 4.8 is vulnerable; other versions may also b=
e affected.
22. EFS Software Easy Chat Server 'registresult.htm' Authentication Bypas=
s Vulnerability
BugTraq ID: 33967
Remote: Yes
Date Published: 2009-03-03
Relevant URL: http://www.securityfocus.com/bid/33967
Summary:
EFS Software Easy Chat Server is prone to an authentication-bypass vulner=
ability because it fails to perform adequate authentication checks.
Attackers can exploit this vulnerability to gain unauthorized access to t=
he affected application, which may aid in further attacks.
Easy Chat Server 2.2 is vulnerable; other versions may also be affected.
23. VUPlayer '.CUE' File Buffer Overflow Vulnerability
BugTraq ID: 33960
Remote: Yes
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33960
Summary:
VUPlayer is prone to a buffer-overflow vulnerability because the applicat=
ion fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
VUPlayer 2.49 is vulnerable; other versions may also be affected.
24. Media Commands Multiple Media File Multiple Heap Buffer Overflow Vuln=
erabilities
BugTraq ID: 33958
Remote: Yes
Date Published: 2009-03-02
Relevant URL: http://www.securityfocus.com/bid/33958
Summary:
Media Commands is prone to multiple heap-based buffer-overflow vulnerabil=
ities because it fails to perform adequate boundary checks on user-suppli=
ed input.
Successfully exploiting these issues may allow remote attackers to execut=
e arbitrary code in the context of the application. Failed exploit attem=
pts will cause denial-of-service conditions.
Media Commands 1.0 is vulnerable; other versions may also be affected.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SQL Server stored procedure encryption
http://www.securityfocus.com/archive/88/501582
2. SecurityFocus Microsoft Newsletter #434
http://www.securityfocus.com/archive/88/501511
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Sophos
Laws, regulations and compliance: Top tips for keeping your data under yo=
ur control=20
=20
http://dinclinx.com/Redirect.aspx?36;4035;35;189;0;5;259;787c0986ab9c445a