SecurityFocus Microsoft Newsletter #436

[email protected] Wed, 18 Mar 2009 15:15:02 -0700
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #436
----------------------------------------

This issue is sponsored by Tripwire

Configuration Assessment: Choosing the Right Solution=20
Configuration assessment lets businesses proactively secure their IT infr=
astructure and achieve compliance with important industry standards and r=
egulations. Learn why configuration assessment is so important, why organ=
izations find it difficult to control system configurations, and what typ=
es of configuration assessment solutions are available.

http://dinclinx.com/Redirect.aspx?36;3065;32;189;0;3;259;458f725ab218caf9


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Contracting For Secure Code
       2. Free Market Filtering
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Icarus 'PGN' File Remote Stack Buffer Overflow Vulnerability
       2. CDex 'ogg' File Buffer Overflow Vulnerability
       3. PHPRunner 'SearchField' Parameter SQL Injection Vulnerability
       4. Talkative IRC 'PRIVMSG' Buffer Overflow Vulnerability
       5. JustSystems Ichitaro Unspecified Code Execution Vulnerability
       6. WinAsm Studio '.wap' Project File Heap-Based Buffer Overflow Vu=
lnerability
       7. Serv-U FTP Server 'MKD' Command Directory Traversal Vulnerabili=
ty
       8. Rosoft Media Player 'rml' File Buffer Overflow Vulnerability
       9. Multiple SlySoft Products Driver IOCTL Request Multiple Local B=
uffer Overflow Vulnerabilities
       10. Apple iTunes Information Disclosure and Denial of Service Vuln=
erabilities
       11. POP Peeper 'Date' Remote Buffer Overflow Vulnerability
       12. PostgreSQL Conversion Encoding Remote Denial of Service Vulner=
ability
       13. Autonomy KeyView Module 'wp6sr.dll' Buffer Overflow Vulnerabil=
ity
       14. RainbowPlayer '.rpl' File Remote Buffer Overflow Vulnerability
       15. PostgreSQL Low Cost Function Information Disclosure Vulnerabil=
ity
       16. MediaCoder '.m3u' File Remote Stack Buffer Overflow Vulnerabil=
ity
       17. eZip Wizard Zip File Stack Remote Buffer Overflow Vulnerabilit=
y
       18. RadASM '.rap' Project File Stack-Based Buffer Overflow Vulnera=
bility
       19. Nokia Multimedia Player '.npl' File Heap Buffer Overflow Vulne=
rability
       20. mks_vir 'mksmonen.sys' IOCTL Request Local Privilege Escalatio=
n Vulnerability
       21. Microsoft Windows Kernel Handle Local Privilege Escalation Vul=
nerability
       22. Microsoft Windows Invalid Pointer Local Privilege Escalation V=
ulnerability
       23. Microsoft Windows SChannel Authentication Spoofing Vulnerabili=
ty
       24. Microsoft Windows WINS Server WPAD and ISATAP Access Validatio=
n Vulnerability
       25. Microsoft Windows Kernel GDI EMF/WMF Remote Code Execution Vul=
nerability
       26. Microsoft Windows DNS Server WPAD Access Validation Vulnerabil=
ity
       27. Microsoft Windows DNS Server Incorrect Caching DNS Spoofing Vu=
lnerability
       28. Microsoft Windows DNS Server Response Caching DNS Spoofing Vul=
nerability
       29. Symantec pcAnywhere Local Format String Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
       1. SecurityFocus Microsoft Newsletter #435
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Contracting For Secure Code
By Chris Wysopal
Forcing suppliers to attest to the security of provided software is gaini=
ng adherents: Just ask Kaspersky Lab.=20
http://www.securityfocus.com/columnists/494

2. Free Market Filtering
By Mark Rasch
The Australian government is considering requiring that Internet service =
providers in that country install filters which would prevent citizens fr=
om accessing tens of thousands of sites that contain "objectionable" mate=
rial.=20
http://www.securityfocus.com/columnists/493


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Icarus 'PGN' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 34167
Remote: Yes
Date Published: 2009-03-18
Relevant URL: http://www.securityfocus.com/bid/34167
Summary:
Icarus is prone to a remote stack-based buffer-overflow vulnerability bec=
ause the application fails to perform adequate boundary checks on user-su=
pplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Icarus 2.0 is vulnerable; other versions may also be affected.

2. CDex 'ogg' File Buffer Overflow Vulnerability
BugTraq ID: 34164
Remote: Yes
Date Published: 2009-03-18
Relevant URL: http://www.securityfocus.com/bid/34164
Summary:
CDex is prone to a buffer-overflow vulnerability because the application =
fails to perform adequate boundary checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

CDex 1.70 (Beta 2) is vulnerable; other versions may also be affected.

3. PHPRunner 'SearchField' Parameter SQL Injection Vulnerability
BugTraq ID: 34146
Remote: Yes
Date Published: 2009-03-17
Relevant URL: http://www.securityfocus.com/bid/34146
Summary:
PHPRunner generates scripts that are prone to an SQL-injection vulnerabil=
ity because they fail to sufficiently sanitize user-supplied data before =
using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.

PHPRunner 4.2 is vulnerable; other versions may also be affected.

4. Talkative IRC 'PRIVMSG' Buffer Overflow Vulnerability
BugTraq ID: 34141
Remote: Yes
Date Published: 2009-03-17
Relevant URL: http://www.securityfocus.com/bid/34141
Summary:
Talkative IRC is prone to a stack-based buffer-overflow vulnerability bec=
ause it fails to bounds-check user-supplied data before copying it into a=
n insufficiently sized buffer.

An attacker can exploit this issue by enticing an unsuspecting user into =
connecting to a malicious IRC server. Successful attacks will allow arbit=
rary code to run within the context of the affected application. Failed e=
xploit attempts will result in a denial-of-service condition.

Talkative IRC 0.4.4.16 is vulnerable; other versions may also be affected=
.

5. JustSystems Ichitaro Unspecified Code Execution Vulnerability
BugTraq ID: 34138
Remote: Yes
Date Published: 2009-03-16
Relevant URL: http://www.securityfocus.com/bid/34138
Summary:
Ichitaro is prone to an unspecified remote code-execution vulnerability.

Attackers may exploit this issue to execute arbitrary code within the con=
text of the vulnerable application. Failed attempts will result in a deni=
al-of-service condition.

Ichitaro 2008 and prior versions are vulnerable.

6. WinAsm Studio '.wap' Project File Heap-Based Buffer Overflow Vulnerabi=
lity
BugTraq ID: 34132
Remote: Yes
Date Published: 2009-03-16
Relevant URL: http://www.securityfocus.com/bid/34132
Summary:
WinAsm Studio is prone to a heap-based buffer-overflow vulnerability beca=
use it fails to perform adequate checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
 WinAsm Studio 5.1.5.0 is vulnerable; other versions may also be affected=
.

7. Serv-U FTP Server 'MKD' Command Directory Traversal Vulnerability
BugTraq ID: 34125
Remote: Yes
Date Published: 2009-03-16
Relevant URL: http://www.securityfocus.com/bid/34125
Summary:
Serv-U FTP Server is prone to a directory-traversal vulnerability because=
 the application fails to sufficiently sanitize user-supplied input.

Exploiting this issue allows an authenticated user to create directories =
outside the FTP root directory, which may lead to other attacks.

Serv-U FTP Server 7.4.0.1 is vulnerable; other versions may also be affec=
ted.

8. Rosoft Media Player 'rml' File Buffer Overflow Vulnerability
BugTraq ID: 34124
Remote: Yes
Date Published: 2009-03-16
Relevant URL: http://www.securityfocus.com/bid/34124
Summary:
Rosoft Media Player is prone to a buffer-overflow vulnerability because t=
he application fails to perform adequate boundary checks on user-supplied=
 input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

9. Multiple SlySoft Products Driver IOCTL Request Multiple Local Buffer O=
verflow Vulnerabilities
BugTraq ID: 34103
Remote: No
Date Published: 2009-03-12
Relevant URL: http://www.securityfocus.com/bid/34103
Summary:
Multiple SlySoft products are prone to multiple buffer-overflow vulnerabi=
lities because they fail to adequately validate user-supplied input.

A local attacker can exploit these issues to crash the affected system, c=
ausing a denial-of-service condition. The attacker may also be able to ru=
n arbitrary code with SYSTEM-level privileges, but this has not been conf=
irmed.

The following applications are vulnerable:

SlySoft AnyDVD 6.5.2.2
SlySoft Virtual CloneDrive 5.4.2.3
SlySoft CloneDVD 2.9.2.0
SlySoft CloneCD 5.3.1.3

10. Apple iTunes Information Disclosure and Denial of Service Vulnerabili=
ties
BugTraq ID: 34094
Remote: Yes
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34094
Summary:
Apple iTunes is prone to an information-disclosure vulnerability and a de=
nial-of-service vulnerability.

Successfully exploiting these issues may allow an attacker to obtain sens=
itive information or cause the affected application to crash, denying ser=
vice to legitimate users.

Versions prior to Apple iTunes 8.1 are vulnerable.

11. POP Peeper 'Date' Remote Buffer Overflow Vulnerability
BugTraq ID: 34093
Remote: Yes
Date Published: 2009-03-12
Relevant URL: http://www.securityfocus.com/bid/34093
Summary:
POP Peeper is prone to a buffer-overflow vulnerability because it fails t=
o properly bounds-check user-supplied data before copying it into an insu=
fficiently sized memory buffer.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n denial-of-service conditions.

POP Peeper 3.4.0.0 is vulnerable; other versions may also be affected.

12. PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
BugTraq ID: 34090
Remote: Yes
Date Published: 2009-03-11
Relevant URL: http://www.securityfocus.com/bid/34090
Summary:
PostgreSQL is prone to a remote denial-of-service vulnerability.

Exploiting this issue may allow attackers to terminate connections to the=
 PostgreSQL server, denying service to legitimate users.

13. Autonomy KeyView Module 'wp6sr.dll' Buffer Overflow Vulnerability
BugTraq ID: 34086
Remote: Yes
Date Published: 2009-03-17
Relevant URL: http://www.securityfocus.com/bid/34086
Summary:
Autonomy KeyView module is prone to a buffer-overflow vulnerability becau=
se it fails to perform adequate boundary checks on user-supplied data bef=
ore copying it to insufficiently sized buffers.

Exploiting this issue will allow an attacker to corrupt memory and to cau=
se denial-of-service conditions or potentially to execute arbitrary code =
in the context of the application using the module.

Multiple products using the KeyView module are affected.

14. RainbowPlayer '.rpl' File Remote Buffer Overflow Vulnerability
BugTraq ID: 34072
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34072
Summary:
RainbowPlayer is prone to a remote buffer-overflow vulnerability because =
the application fails to perform adequate boundary checks on user-supplie=
d input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

RainbowPlayer 0.91 is vulnerable; other versions may also be affected.

15. PostgreSQL Low Cost Function Information Disclosure Vulnerability
BugTraq ID: 34069
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34069
Summary:
PostgreSQL is prone to an information-disclosure vulnerability.=20

Local attackers can exploit this issue to obtain sensitive information th=
at may lead to further attacks.=20

PostgreSQL 8.3.6 is vulnerable; other versions may also be affected.

16. MediaCoder '.m3u' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 34051
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34051
Summary:
MediaCoder is prone to a remote stack-based buffer-overflow vulnerability=
 because the application fails to perform adequate boundary checks on use=
r-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

MediaCoder 6.2.4275 is vulnerable; other versions may also be affected.

17. eZip Wizard Zip File Stack Remote Buffer Overflow Vulnerability
BugTraq ID: 34044
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34044
Summary:
eZip Wizard is prone to a remote stack-based buffer-overflow vulnerabilit=
y because the application fails to perform adequate boundary checks on us=
er-supplied data.

An attacker can exploit this issue to execute arbitrary code with the pri=
vileges of the user running the affected application. Failed exploit atte=
mpts will result in a denial-of-service condition.

eZip Wizard 3.0 is vulnerable; other versions may also be affected.

18. RadASM '.rap' Project File Stack-Based Buffer Overflow Vulnerability
BugTraq ID: 34042
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34042
Summary:
RadASM is prone to a stack-based buffer-overflow vulnerability because it=
 fails to perform adequate checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
=20
 RadASM 2.2.1.5 is vulnerable; other versions may also be affected.

19. Nokia Multimedia Player '.npl' File Heap Buffer Overflow Vulnerabilit=
y
BugTraq ID: 34041
Remote: Yes
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34041
Summary:
Nokia Multimedia Player is prone to a heap-based buffer-overflow vulnerab=
ility because it fails to perform adequate boundary checks on user-suppli=
ed input.

Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of  the application. Failed exploit attempt=
s will cause denial-of-service conditions.

Nokia Multimedia Player 1.0 is vulnerable; other versions may also be aff=
ected.

20. mks_vir 'mksmonen.sys' IOCTL Request Local Privilege Escalation Vulne=
rability
BugTraq ID: 34039
Remote: No
Date Published: 2009-03-09
Relevant URL: http://www.securityfocus.com/bid/34039
Summary:
The 'mks_vir' program is prone a local privilege-escalation vulnerability=
.

An attacker can exploit this issue to execute arbitrary code with elevate=
d privileges; this may aid in further attacks.

 Versions prior to mks_vir 9 Beta 1.2.0.0 build 297 are vulnerable.

21. Microsoft Windows Kernel Handle Local Privilege Escalation Vulnerabil=
ity
BugTraq ID: 34027
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34027
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

22. Microsoft Windows Invalid Pointer Local Privilege Escalation Vulnerab=
ility
BugTraq ID: 34025
Remote: No
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34025
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
that occurs in the Windows kernel.

An attacker can exploit this issue to execute arbitrary code with kernel-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.

23. Microsoft Windows SChannel Authentication Spoofing Vulnerability
BugTraq ID: 34015
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34015
Summary:
Microsoft Windows SChannel is prone to an authentication-spoofing vulnera=
bility because it fails to properly validate certain client-server certif=
icate exchanges.

Successful exploits will allow attackers to authenticate to trusted serve=
rs by spoofing a legitimate user's credentials. This may aid in further a=
ttacks.

24. Microsoft Windows WINS Server WPAD and ISATAP Access Validation Vulne=
rability
BugTraq ID: 34013
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34013
Summary:
The Microsoft Windows WINS Server is prone to an access-validation vulner=
ability because the software fails to properly restrict access when defin=
ing WPAD (Web Proxy Autodiscovery Protocol) and ISATAP (Intra-Site Automa=
tic Tunnel Addressing Protocol) entries.

An authenticated attacker may exploit this issue to create a WPAD or ISAT=
AP WINS entry. This may aid in man-in-the-middle and spoofing attacks. Ot=
her attacks are also possible.

25. Microsoft Windows Kernel GDI EMF/WMF Remote Code Execution Vulnerabil=
ity
BugTraq ID: 34012
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/34012
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability.

An attacker can exploit this issue by enticing an unsuspecting victim to =
open a malicious EMF or WMF image file.=20

Successfully exploiting this issue will allow attackers to execute arbitr=
ary code with kernel-level privileges, completely compromising affected c=
omputers. Failed exploit attempts will result in a denial-of-service cond=
ition.

26. Microsoft Windows DNS Server WPAD Access Validation Vulnerability
BugTraq ID: 33989
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/33989
Summary:
The Microsoft Windows DNS Server is prone to an access-validation vulnera=
bility because the software fails to properly restrict access when defini=
ng WPAD (Web Proxy Autodiscovery Protocol) entries.

An authenticated attacker may exploit this issue to create a WPAD DNS ent=
ry. This may aid in man-in-the-middle and spoofing attacks. Other attacks=
 are also possible.

27. Microsoft Windows DNS Server Incorrect Caching DNS Spoofing Vulnerabi=
lity
BugTraq ID: 33988
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/33988
Summary:
The Microsoft Windows DNS Server is prone to a DNS-spoofing vulnerability=
 because the software fails to cache responses to specially crafted DNS q=
ueries.
=20
Successfully exploiting this issue allows remote attackers to spoof DNS r=
eplies, allowing them to redirect network traffic and to launch man-in-th=
e-middle attacks.

28. Microsoft Windows DNS Server Response Caching DNS Spoofing Vulnerabil=
ity
BugTraq ID: 33982
Remote: Yes
Date Published: 2009-03-10
Relevant URL: http://www.securityfocus.com/bid/33982
Summary:
The Microsoft Windows DNS Server is prone to a DNS-spoofing vulnerability=
 because the software fails to properly reuse cached responses.
=20
Successfully exploiting this issue allows remote attackers to spoof DNS r=
eplies, allowing them to redirect network traffic and to launch man-in-th=
e-middle attacks.

29. Symantec pcAnywhere Local Format String Vulnerability
BugTraq ID: 33845
Remote: No
Date Published: 2009-03-17
Relevant URL: http://www.securityfocus.com/bid/33845
Summary:
Symantec pcAnywhere is prone to a local format-string vulnerability.

A local attacker may exploit this issue to crash the affected application=
, resulting in a denial-of-service condition. The attacker may also be ab=
le to execute arbitrary code within the context of the application, but t=
his has not been confirmed.
=20
 pcAnywhere 12.0, 12.1, and 12.5 are vulnerable; other versions may also =
be affected.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. SecurityFocus Microsoft Newsletter #435
http://www.securityfocus.com/archive/88/501694

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Tripwire

Configuration Assessment: Choosing the Right Solution=20
Configuration assessment lets businesses proactively secure their IT infr=
astructure and achieve compliance with important industry standards and r=
egulations. Learn why configuration assessment is so important, why organ=
izations find it difficult to control system configurations, and what typ=
es of configuration assessment solutions are available.

http://dinclinx.com/Redirect.aspx?36;3065;32;189;0;3;259;458f725ab218caf9