SecurityFocus Microsoft Newsletter #440

[email protected] Fri, 17 Apr 2009 11:02:41 -0600
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #440
----------------------------------------

This issue is sponsored by Cisco

Five Ways to Know Your Wireless Security

A wireless network can help your employees stay productive as they move a=
round your company. But to take advantage of the benefits of wireless net=
working, you need to be sure that your network is safe from hackers and u=
nauthorized users. Every device in a wireless network is important to sec=
urity. Because a wireless LAN (WLAN) is a mobile network, you need a thor=
ough, multilayered approach to safeguard traffic.

http://dinclinx.com/Redirect.aspx?36;4328;50;189;0;5;259;b3682945b0c3f7c4


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Facebook, Privacy and Contracts
       2. Act Locally, Pwn Globally
II.  MICROSOFT VULNERABILITY SUMMARY
       1. MagicISO CCD/Cue File Heap Overflow Vulnerability
       2. MiniWeb Source Code Information Disclosure Vulnerability
       3. MiniWeb Remote Buffer Overflow Vulnerability
       4. Elecard AVC HD Player '.xpl' File Remote Stack Buffer Overflow =
Vulnerability
       5. Apollo 'm3u' Playlist File Heap Buffer Overflow Vulnerability
       6. Microsoft Windows Media Player MID File Parsing Integer Overflo=
w Vulnerability
       7. Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer =
Overflow Vulnerabilities
       8. Zervit 'http.c' Remote Buffer Overflow Vulnerability
       9. Mini-stream Software RM-MP3 Converter '.pls' File Remote Stack =
Buffer Overflow Vulnerability
       10. Multiple Mini-stream Software Products '.m3u' File Remote Stac=
k Buffer Overflow Vulnerability
       11. FTPDMIN 'RNFR' Command Buffer Overflow Vulnerability
       12. Microsoft Internet Explorer File Download Denial of Service Vu=
lnerability
       13. Xilisoft Video Converter Wizard '.CUE'  File Stack Buffer Over=
flow Vulnerability
       14. Microsoft WordPad Word 97 Converter Remote Code Execution Vuln=
erability
       15. Microsoft Word 2000 WordPerfect Converter Remote Code Executio=
n Vulnerability
       16. Microsoft Windows 'atapi.sys' Local Privilege Escalation Vulne=
rability
       17. Microsoft DirectX DirectShow MJPEG Video Decompression Remote =
Code Execution  Vulnerability
       18. SWF Opener Buffer Overflow Vulnerability
       19. HP ProCurve Manager and ProCurve Manager Plus Unauthorized Acc=
ess Vulnerability
       20. Microsoft April 2009 Advance Notification Multiple Vulnerabili=
ties
       21. EMC RepliStor Multiple Remote Heap Based Buffer Overflow Vulne=
rabilities
       22. Microsoft Windows Thread Pool ACL Local Privilege Escalation V=
ulnerability
       23. Microsoft Windows RPCSS Service Isolation Local Privilege Esca=
lation Vulnerability
       24. Microsoft Windows WMI Service Isolation Local Privilege Escala=
tion Vulnerability
       25. Microsoft Windows NTLM Credential Reflection Remote Code Execu=
tion Vulnerability
       26. Microsoft Internet Explorer Page Transition Remote Code Execut=
ion Vulnerability
       27. Microsoft WinHTTP Server Name Mismatch Certificate Validation =
Security Bypass Vulnerability
       28. Microsoft WinHTTP Integer Underflow Memory Corruption Remote C=
ode Execution Vulnerability
       29. Microsoft Internet Explorer Uninitialized Memory Variant Three=
 Remote Code Execution Vulnerability
       30. Microsoft Internet Explorer Uninitialized Memory Variant Two R=
emote Code Execution Vulnerability
       31. Microsoft Internet Explorer Uninitialized Memory Variant One R=
emote Code Execution Vulnerability
       32. Microsoft ISA Server and Forefront Threat Management Gateway C=
ross-Site Scripting Vulnerability
       33. Microsoft ISA Server and Forefront Threat Management Gateway D=
enial of Service Vulnerability
       34. Microsoft Excel Malformed Object Remote Memory Corruption Vuln=
erability
       35. OpenAFS Unix Cache Manager Heap-Based Buffer Overflow Vulnerab=
ility
       36. OpenAFS Error Codes Remote Denial of Service Vulnerabiliy
       37. JustSystems Ichitaro RTF File Buffer Overflow Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Facebook, Privacy and Contracts
On February 4, the social networking site Facebook made a minor change to=
 its terms of service - the online contract that every user must agree to=
 when they create an account.=20
Facebook was trying to solve a legitimate problem: People who deleted the=
ir accounts did not realize that information that they shared with other =
users would persist on their Facebook friends' accounts. Thus, they neede=
d some way of telling users that the information might remain.
http://www.securityfocus.com/columnists/497

2. Act Locally, Pwn Globally
By Jeffrey Carr
On December 24, 2008, the Pakistani Whackerz Cr3w defaced a part of India=
's critical infrastructure, the Eastern Railway system Web site. The defa=
cement appeared on a scroll feed which read: "Cyber war has been declared=
 on Indian cyberspace by Whackerz- Pakistan (24 Dec-2008)."=20
http://www.securityfocus.com/columnists/496


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. MagicISO CCD/Cue File Heap Overflow Vulnerability
BugTraq ID: 34574
Remote: Yes
Date Published: 2009-04-16
Relevant URL: http://www.securityfocus.com/bid/34574
Summary:
MagicISO is prone to a heap-overflow vulnerability that may be triggered =
by a malicious '.ccd' or '.cue' file.=20

A successful exploit will crash the application. It may also allow an att=
acker to execute arbitrary code in the context of the application but thi=
s has not been confirmed.

2. MiniWeb Source Code Information Disclosure Vulnerability
BugTraq ID: 34565
Remote: Yes
Date Published: 2009-04-16
Relevant URL: http://www.securityfocus.com/bid/34565
Summary:
MiniWeb is prone to a vulnerability that lets attackers access source cod=
e because it fails to properly sanitize user-supplied input.=20

An attacker can exploit this vulnerability to retrieve arbitrary files fr=
om the vulnerable computer in the context of the webserver process. Infor=
mation obtained may aid in further attacks.

This issue affects unknown versions of MiniWeb.  We will update this BID =
when further details are available.

3. MiniWeb Remote Buffer Overflow Vulnerability
BugTraq ID: 34563
Remote: Yes
Date Published: 2009-04-16
Relevant URL: http://www.securityfocus.com/bid/34563
Summary:
MiniWeb is prone to a remote buffer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

4. Elecard AVC HD Player '.xpl' File Remote Stack Buffer Overflow Vulnera=
bility
BugTraq ID: 34560
Remote: Yes
Date Published: 2009-04-16
Relevant URL: http://www.securityfocus.com/bid/34560
Summary:
Elecard AVC HD Player is prone to a remote stack-based buffer-overflow vu=
lnerability because the application fails to perform adequate boundary ch=
ecks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

5. Apollo 'm3u' Playlist File Heap Buffer Overflow Vulnerability
BugTraq ID: 34554
Remote: Yes
Date Published: 2009-04-16
Relevant URL: http://www.securityfocus.com/bid/34554
Summary:
Apollo is prone to a heap-based buffer-overflow  vulnerability because th=
e application fails to bounds-check user-supplied data before copying it =
into an insufficiently sized buffer.=20

Attackers can execute arbitrary code in the context of the affected appli=
cation. Failed exploit attempts will result in a denial-of-service condit=
ion.

Apollo 37zz is vulnerable; other versions may also be affected.

6. Microsoft Windows Media Player MID File Parsing Integer Overflow Vulne=
rability
BugTraq ID: 34534
Remote: Yes
Date Published: 2009-04-15
Relevant URL: http://www.securityfocus.com/bid/34534
Summary:
Microsoft Windows Media Player is prone to an integer-overflow vulnerabil=
ity.

An attacker can exploit this issue by tricking an unsuspecting victim int=
o opening a malicious file with the vulnerable application. A successful =
exploit will allow the attacker to execute arbitrary code within the cont=
ext of the affected application. Failed exploit attempts will result in a=
 denial of service.

Windows Media Player 11 is vulnerable; other versions may also be affecte=
d.

7. Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflo=
w Vulnerabilities
BugTraq ID: 34532
Remote: Yes
Date Published: 2009-04-15
Relevant URL: http://www.securityfocus.com/bid/34532
Summary:
The Microsoft Intelligent Application Gateway (IAG) 2007 Client Component=
s ActiveX Control is prone to multiple stack-based buffer-overflow vulner=
abilities because the application fails to perform adequate boundary chec=
ks on user-supplied data. The ActiveX control is identified by CLSID:

8D9563A9-8D5F-459B-87F2-BA842255CB9A

Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
 (typically Internet Explorer). Failed exploit attempts likely result in =
denial-of-service conditions.

NOTE: IAG was formerly known as Whale Communications Intelligent Applicat=
ion Gateway.

Versions prior to IAG 2007 3.7 SP2 are vulnerable.

8. Zervit 'http.c' Remote Buffer Overflow Vulnerability
BugTraq ID: 34530
Remote: Yes
Date Published: 2009-04-15
Relevant URL: http://www.securityfocus.com/bid/34530
Summary:
Zervit is prone to a remote buffer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

Zervit 0.2 is vulnerable; other versions may also be affected.

9. Mini-stream Software RM-MP3 Converter '.pls' File Remote Stack Buffer =
Overflow Vulnerability
BugTraq ID: 34514
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34514
Summary:
Mini-stream Software RM-MP3 Converter is prone to a remote stack-based bu=
ffer-overflow vulnerability because it fails to perform adequate checks o=
n user-supplied input.

Successfully exploiting this issue may allow remote attackers to execute =
arbitrary code in the context of the application. Failed attacks will cau=
se denial-of-service conditions.

10. Multiple Mini-stream Software Products '.m3u' File Remote Stack Buffe=
r Overflow Vulnerability
BugTraq ID: 34494
Remote: Yes
Date Published: 2009-04-13
Relevant URL: http://www.securityfocus.com/bid/34494
Summary:
Multiple Mini-stream Software products are prone to a remote stack-based =
buffer-overflow vulnerability because the applications fail to perform ad=
equate boundary checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

11. FTPDMIN 'RNFR' Command Buffer Overflow Vulnerability
BugTraq ID: 34479
Remote: Yes
Date Published: 2009-04-11
Relevant URL: http://www.securityfocus.com/bid/34479
Summary:
FTPDMIN is prone to a buffer-overflow vulnerability.=20

A successful exploit may allow attackers to execute arbitrary code in the=
 context of the vulnerable service. Failed exploit attempts will likely c=
ause denial-of-service conditions.

12. Microsoft Internet Explorer File Download Denial of Service Vulnerabi=
lity
BugTraq ID: 34478
Remote: Yes
Date Published: 2009-04-11
Relevant URL: http://www.securityfocus.com/bid/34478
Summary:
Microsoft Internet Explorer is prone to a remote denial-of-service vulner=
ability.=20

Successful exploits can allow attackers to hang the affected browser, res=
ulting in denial-of-service conditions.

13. Xilisoft Video Converter Wizard '.CUE'  File Stack Buffer Overflow Vu=
lnerability
BugTraq ID: 34472
Remote: Yes
Date Published: 2009-04-10
Relevant URL: http://www.securityfocus.com/bid/34472
Summary:
Xilisoft Video Converter Wizard is prone to a stack-based buffer-overflow=
 vulnerability because the application fails to perform adequate boundary=
 checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Xilisoft Video Converter Wizard 3 is vulnerable; other versions may also =
be affected.

14. Microsoft WordPad Word 97 Converter Remote Code Execution Vulnerabili=
ty
BugTraq ID: 34470
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34470
Summary:
Microsoft WordPad is prone to a remote code-execution vulnerability becau=
se of a stack-based buffer overflow that may result in corrupted memory.

An attacker could exploit this issue to execute arbitrary code with the p=
rivileges of the currently logged-in user. Failed exploit attempts may re=
sult in denial-of-service conditions.

15. Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulne=
rability
BugTraq ID: 34469
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34469
Summary:
Microsoft Word 2000 is prone to a remote code-execution vulnerability bec=
ause it fails to properly validate an unspecified string when parsing a W=
ordPerfect document.

An attacker could exploit this issue to execute arbitrary code with the p=
rivileges of the currently logged-in user. Failed exploit attempts may re=
sult in denial-of-service conditions.

16. Microsoft Windows 'atapi.sys' Local Privilege Escalation Vulnerabilit=
y
BugTraq ID: 34466
Remote: No
Date Published: 2009-04-09
Relevant URL: http://www.securityfocus.com/bid/34466
Summary:
Microsoft Windows is prone to a local privilege-escalation vulnerability =
because it fails to adequately handle user-supplied input.

An attacker can exploit this issue to execute arbitrary code with SYSTEM-=
level privileges. Successfully exploiting this issue will result in the c=
omplete compromise of affected computers.  Failed exploits will cause a d=
enial of service.

17. Microsoft DirectX DirectShow MJPEG Video Decompression Remote Code Ex=
ecution  Vulnerability
BugTraq ID: 34460
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34460
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability becau=
se the DirectShow component fails to properly handle compressed media fil=
es.

Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the user running the application that uses =
DirectX. Failed exploit attempts will result in a denial-of-service condi=
tion.

18. SWF Opener Buffer Overflow Vulnerability
BugTraq ID: 34459
Remote: Yes
Date Published: 2009-04-09
Relevant URL: http://www.securityfocus.com/bid/34459
Summary:
SWF Opener is prone to a remote buffer-overflow vulnerability because it =
fails to adequately bounds-check user-supplied data before copying it to =
an insufficiently sized memory buffer.=20

Successful exploits may allow an attacker to execute arbitrary code with =
the privileges of the user running the affected application. Failed explo=
it attempts will likely result in denial-of-service conditions.

SWF Opener 1.3 is vulnerable; other versions may also be affected.

19. HP ProCurve Manager and ProCurve Manager Plus Unauthorized Access Vul=
nerability
BugTraq ID: 34451
Remote: Yes
Date Published: 2009-04-09
Relevant URL: http://www.securityfocus.com/bid/34451
Summary:
HP ProCurve Manager and ProCurve Manager Plus are prone to an unspecified=
 unauthorized-access vulnerability. Remote attackers may exploit this iss=
ue to gain unauthorized access to data.

The following are vulnerable:

 ProCurve Manager 3.2 and earlier
 ProCurve Manager Plus 3.2 and eariler

20. Microsoft April 2009 Advance Notification Multiple Vulnerabilities
BugTraq ID: 34450
Remote: Yes
Date Published: 2009-04-09
Relevant URL: http://www.securityfocus.com/bid/34450
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing eight security bulletins on April 14, 2009. The highest severity rat=
ing for these issues is 'Critical'.

These issues affect Windows, Internet Explorer, Office, Excel, and ISA Se=
rver.

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

Individual records will be created to document these issues when the bull=
etins are released.

21. EMC RepliStor Multiple Remote Heap Based Buffer Overflow Vulnerabilit=
ies
BugTraq ID: 34449
Remote: Yes
Date Published: 2009-04-09
Relevant URL: http://www.securityfocus.com/bid/34449
Summary:
EMC RepliStor is prone to multiple remote heap-based buffer-overflow vuln=
erabilities because it fails to perform adequate boundary checks on user-=
supplied input.

A remote attacker can exploit these issues to execute arbitrary code with=
 SYSTEM-level privileges. Successfully exploiting this issue will result =
in the complete compromise of affected computers. Failed exploit attempts=
 will result in a denial-of-service condition.

Versions prior to RepliStor 6.2 SP5 and RepliStor 6.3 SP2 are vulnerable.

22. Microsoft Windows Thread Pool ACL Local Privilege Escalation Vulnerab=
ility
BugTraq ID: 34444
Remote: No
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34444
Summary:
Microsoft Windows is prone to a privilege-escalation vulnerability.

Successful exploits may allow attackers to elevate their privileges to Lo=
calSystem, which would facilitate the complete compromise of affected com=
puters.

The issue affects the following:

Windows Vista
Windows Server 2008

23. Microsoft Windows RPCSS Service Isolation Local Privilege Escalation =
Vulnerability
BugTraq ID: 34443
Remote: No
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34443
Summary:
Microsoft Windows is prone to a privilege-escalation vulnerability.

Successful exploits may allow attackers to elevate their privileges to Lo=
calSystem, which would facilitate the complete compromise of affected com=
puters.

The issue affects the following:

Windows XP SP2
Windows Server 2003

24. Microsoft Windows WMI Service Isolation Local Privilege Escalation Vu=
lnerability
BugTraq ID: 34442
Remote: No
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34442
Summary:
Microsoft Windows is prone to a privilege-escalation vulnerability.

Successful exploits may allow attackers to elevate their privileges to Lo=
calSystem, which would facilitate the complete compromise of affected com=
puters.

The issue affects the following:

Windows XP SP2
Windows Server 2003
Windows Vista
Windows Server 2008

25. Microsoft Windows NTLM Credential Reflection Remote Code Execution Vu=
lnerability
BugTraq ID: 34439
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34439
Summary:
Microsoft Windows is prone to a vulnerability that could let attackers re=
play NTLM (NT LAN Manager) credentials. A successful exploit would let an=
 attacker execute arbitrary code in the context of the affected user.

26. Microsoft Internet Explorer Page Transition Remote Code Execution Vul=
nerability
BugTraq ID: 34438
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34438
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the computer. Failed attacks will cause den=
ial-of-service conditions.

27. Microsoft WinHTTP Server Name Mismatch Certificate Validation Securit=
y Bypass Vulnerability
BugTraq ID: 34437
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34437
Summary:
Microsoft Windows HTTP Services (WinHTTP) is prone to a security-bypass v=
ulnerability because of an error in verifying website certificates.

Successfully exploiting this issue allows attackers to perform man-in-the=
-middle attacks or impersonate trusted servers, which will aid in further=
 attacks.

28. Microsoft WinHTTP Integer Underflow Memory Corruption Remote Code Exe=
cution Vulnerability
BugTraq ID: 34435
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34435
Summary:
Microsoft Windows HTTP Services (WinHTTP) is prone to a remote code-execu=
tion vulnerability.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 an affected application and possibly the computer. Failed attacks will c=
ause denial-of-service conditions.

29. Microsoft Internet Explorer Uninitialized Memory Variant Three Remote=
 Code Execution Vulnerability
BugTraq ID: 34426
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34426
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the computer. Failed attacks may cause deni=
al-of-service conditions.

30. Microsoft Internet Explorer Uninitialized Memory Variant Two Remote C=
ode Execution Vulnerability
BugTraq ID: 34424
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34424
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the computer. Failed attacks may cause deni=
al-of-service conditions.

31. Microsoft Internet Explorer Uninitialized Memory Variant One Remote C=
ode Execution Vulnerability
BugTraq ID: 34423
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34423
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity.

Attackers can exploit this issue to execute arbitrary code in the context=
 of the user running the application. Successful exploits will compromise=
 the application and possibly the computer. Failed attacks may cause deni=
al-of-service conditions.

32. Microsoft ISA Server and Forefront Threat Management Gateway Cross-Si=
te Scripting Vulnerability
BugTraq ID: 34416
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34416
Summary:
Microsoft ISA (Internet Security and Acceleration) Server and Forefront T=
hreat Management Gateway (TMG) are prone to a cross-site scripting vulner=
ability because the software fails to properly sanitize user-supplied inp=
ut.=20

An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal potentially sensitive information and lau=
nch other attacks.

33. Microsoft ISA Server and Forefront Threat Management Gateway Denial o=
f Service Vulnerability
BugTraq ID: 34414
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34414
Summary:
Microsoft ISA Server and Forefront Threat Management Gateway are prone to=
 a remote denial-of-service vulnerability.

A remote, anonymous attacker could exploit this issue to cause the Web pr=
oxy listener to become unresponsive, denying service legitimate users.

34. Microsoft Excel Malformed Object Remote Memory Corruption Vulnerabili=
ty
BugTraq ID: 34413
Remote: Yes
Date Published: 2009-04-14
Relevant URL: http://www.securityfocus.com/bid/34413
Summary:
Microsoft Excel is prone to a memory-corruption vulnerability.=20

Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file.

Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application.

35. OpenAFS Unix Cache Manager Heap-Based Buffer Overflow Vulnerability
BugTraq ID: 34407
Remote: Yes
Date Published: 2009-04-07
Relevant URL: http://www.securityfocus.com/bid/34407
Summary:
OpenAFS is prone to a remote heap-based buffer-overflow vulnerability bec=
ause it fails to properly bounds-check user-supplied data before copying =
it to an insufficiently sized memory buffer in the Unix cache manager. Th=
e issue occurs when the application processes RX packets in a client cont=
ext.

An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the Unix cache manager, resulting in a complete compromise of the a=
ffected computer. Failed exploit attempts will likely result in a denial =
of service.

The issue affects these versions:

OpenAFS Unix clients 1.0 through 1.4.8
OpenAFS Unix clients 1.5.0 through 1.5.58

Note that Mac OS X clients are not affected.

36. OpenAFS Error Codes Remote Denial of Service Vulnerabiliy
BugTraq ID: 34404
Remote: Yes
Date Published: 2009-04-07
Relevant URL: http://www.securityfocus.com/bid/34404
Summary:
OpenAFS file server is prone to a denial-of-service vulnerability that oc=
curs on computers running the Linux kernel.
=20
Successfully exploiting this issue allows attackers to cause a kernel pan=
ic, denying service to legitimate users.

The issue affects these versions:

OpenAFS 1.0 through 1.4.8=20
OpenAFS 1.5.0 through 1.5.58

37. JustSystems Ichitaro RTF File Buffer Overflow Vulnerability
BugTraq ID: 34403
Remote: Yes
Date Published: 2009-04-07
Relevant URL: http://www.securityfocus.com/bid/34403
Summary:
Ichitaro is prone to a remote buffer-overflow vulnerability.

Attackers may exploit this issue to execute arbitrary code within the con=
text of the vulnerable application. Failed attempts will result in a deni=
al-of-service condition.

Ichitaro 2009 and prior versions are vulnerable.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Cisco

Five Ways to Know Your Wireless Security

A wireless network can help your employees stay productive as they move a=
round your company. But to take advantage of the benefits of wireless net=
working, you need to be sure that your network is safe from hackers and u=
nauthorized users. Every device in a wireless network is important to sec=
urity. Because a wireless LAN (WLAN) is a mobile network, you need a thor=
ough, multilayered approach to safeguard traffic.

http://dinclinx.com/Redirect.aspx?36;4328;50;189;0;5;259;b3682945b0c3f7c4