SecurityFocus Microsoft Newsletter #448
[email protected] Tue, 14 Jul 2009 17:30:21 -0600
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #448
----------------------------------------
This issue is sponsored by Ironkey
INTRODUCING THE WORLD'S ONLY FIPS 140-2 LEVEL 3 VALIDATED USB FLASH DRIVE
=20
Designed to meet the needs of military, government and demanding enterpri=
se users, the IronKey. S200 series USB flash drives have passed the strin=
gent Security Level 3 tests for the FIPS 140-2 standard. A rugged, tamper=
-resistant and tamper-evident enclosure protects the critical components,=
while strong AES 256-bit hardware encryption and active malware defenses=
safeguard even the most sensitive data. Enterprise-class central managem=
ent capabilities also make it easy to enforce security policies on fleets=
of drives and even remotely destroy drives in the field.=20
Learn more at https://www.ironkey.com/S200_Launch
------------------------------------------------------------------
I. FRONT AND CENTER
1. Hacker-Tool Law Still Does Little
2. A Botnet by Any Other Name
II. MICROSOFT VULNERABILITY SUMMARY
1. Icarus '.icp' File Remote Stack Buffer Overflow Vulnerability
2. Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Executi=
on Vulnerability
3. LibTIFF Multiple Remote Integer Overflow Vulnerabilities
4. Wyse Device Manager Unspecified Remote Buffer Overflow Vulnerab=
ility
5. Microsoft Office Web Components ActiveX Control 'msDataSourceOb=
ject' Code Execution Vulnerability
6. Pirch IRC Client Remote Buffer Overflow Vulnerability
7. Microsoft ISA Server Radius OTP Authentication Bypass Vulnerabi=
lity=20
8. Microsoft Internet Explorer 'AddFavorite' Method Denial of Serv=
ice Vulnerability
9. Microsoft July 2009 Advance Notification Multiple Vulnerabiliti=
es
10. Microsoft DirectX DirectShow Length Record Remote Code Executi=
on Vulnerability
11. Bugzilla Bug Status Modification Security Bypass Vulnerability
12. Microsoft Virtual PC and Virtual Server Privilege Escalation V=
ulnerability
13. Microsoft DirectX DirectShow Pointer Validation Remote Code Ex=
ecution Vulnerability
14. Microsoft Publisher Object Handler Data Pointer Dereference Re=
mote Code Execution Vulnerability
15. Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified R=
emote Memory Corruption Vulnerability
16. Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Co=
de Execution Vulnerability
17. Microsoft Windows Embedded OpenType Font Engine Integer Overfl=
ow Vulnerability
18. Microsoft Windows Embedded OpenType Font Engine Heap Overflow =
Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Hacker-Tool Law Still Does Little
By Mark Rasch
On August 10, 2007, a new section of the German Penal code went into effe=
ct. The statute, intended to implement certain provisions of the Council =
of Europe Treaty on Cybercrime, could be interpreted to make the creation=
or distribution of computer security software a criminal offense.=20
http://www.securityfocus.com/columnists/502
2. A Botnet by Any Other Name
By Gubter Ollmann
The news has been awash the last few weeks with fears over globe-spanning=
botnets and their criminal intent: Conficker managed to hog the limeligh=
t for well over a month, and then came Finjan's disclosure of a previousl=
y unknown - and currently unnamed - botnet consisting of some 1.9 million=
malicious agents.=20
http://www.securityfocus.com/columnists/501
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Icarus '.icp' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 35667
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35667
Summary:
Icarus is prone to a remote stack-based buffer-overflow vulnerability bec=
ause the application fails to perform adequate boundary checks on user-su=
pplied input.
Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.
Icarus 2.0 is vulnerable; other versions may also be affected.
2. Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vuln=
erability
BugTraq ID: 35660
Remote: Yes
Date Published: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35660
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability.=20
Successful exploits may allow an attacker to execute arbitrary code in th=
e context of the user running the affected application. Failed attempts w=
ill likely result in denial-of-service conditions.
The issue affects Firefox 3.5; other versions may also be vulnerable.
NOTE: Remote code execution was confirmed in Firefox 3.5 running on Micro=
soft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP=
3.
3. LibTIFF Multiple Remote Integer Overflow Vulnerabilities
BugTraq ID: 35652
Remote: Yes
Date Published: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35652
Summary:
LibTIFF is prone to multiple remote integer-overflow vulnerabilities beca=
use it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary malicious code=
in the context of a user running an application that uses the affected l=
ibrary. Failed exploit attempts will likely crash the application.
LibTIFF 3.8.2, 3.9, and 4.0 are vulnerable; other versions may also be a=
ffected.
4. Wyse Device Manager Unspecified Remote Buffer Overflow Vulnerability
BugTraq ID: 35649
Remote: Yes
Date Published: 2009-07-10
Relevant URL: http://www.securityfocus.com/bid/35649
Summary:
Wyse Device Manager is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.
5. Microsoft Office Web Components ActiveX Control 'msDataSourceObject' C=
ode Execution Vulnerability
BugTraq ID: 35642
Remote: Yes
Date Published: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35642
Summary:
Microsoft Office Web Components is prone to a remote code-execution vulne=
rability that affects the OWC Spreadsheet ActiveX control. The control is=
identified by the following CLSIDs:
0002E541-0000-0000-C000-000000000046
0002E559-0000-0000-C000-000000000046
An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted site.
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
6. Pirch IRC Client Remote Buffer Overflow Vulnerability
BugTraq ID: 35639
Remote: Yes
Date Published: 2009-07-12
Relevant URL: http://www.securityfocus.com/bid/35639
Summary:
Pirch IRC is prone to a remote buffer-overflow vulnerability because it f=
ails to bounds-check user-supplied data before copying it into an insuffi=
ciently sized buffer.
An attacker can exploit this issue by enticing an unsuspecting user into =
connecting to a malicious IRC server. Successful attacks will allow arbit=
rary code to run within the context of the affected application. Failed e=
xploit attempts will result in a denial-of-service condition.
Pirch IRC 98 is vulnerable; other versions may also be affected.
NOTE: The vulnerability may be related to the issue described in BID 5079=
. We will update the BID when more information emerges.
7. Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability=20
BugTraq ID: 35631
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35631
Summary:
Microsoft ISA Server is prone to an authentication-bypass vulnerability.
An attacker with knowledge of a valid account name can exploit this issue=
to bypass authentication and gain access to arbitrary resources within t=
he context of the selected account.
8. Microsoft Internet Explorer 'AddFavorite' Method Denial of Service Vul=
nerability
BugTraq ID: 35620
Remote: Yes
Date Published: 2009-07-09
Relevant URL: http://www.securityfocus.com/bid/35620
Summary:
Microsoft Internet Explorer is prone to a remote denial-of-service vulner=
ability.=20
Successful exploits can allow attackers to crash the affected browser, re=
sulting in denial-of-service conditions. Reports indicate that this issue=
may be used to corrupt process memory and be leveraged to execute code, =
but this has not been confirmed.
Internet Explorer 7 and 8 are known to be vulnerable; other versions may =
be affected as well.
9. Microsoft July 2009 Advance Notification Multiple Vulnerabilities
BugTraq ID: 35617
Remote: Yes
Date Published: 2009-07-09
Relevant URL: http://www.securityfocus.com/bid/35617
Summary:
Microsoft has released advance notification that on July 14, 2009 the ven=
dor will be releasing six security bulletins covering multiple issues. Th=
e highest severity rating for these issues is 'Critical'.
These issues affect the following:
Windows
DirectX
Virtual PC
Virtual Server
ISA Server
Publisher
Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.
We will create individual records to better document these issues when th=
e bulletins are released.
10. Microsoft DirectX DirectShow Length Record Remote Code Execution Vuln=
erability
BugTraq ID: 35616
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35616
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability that =
resides in the DirectShow component.
Successful exploits allow remote attackers to execute arbitrary code in t=
he context of the user running the application that uses DirectX. Failed =
exploit attempts will result in a denial-of-service condition.
11. Bugzilla Bug Status Modification Security Bypass Vulnerability
BugTraq ID: 35604
Remote: Yes
Date Published: 2009-07-08
Relevant URL: http://www.securityfocus.com/bid/35604
Summary:
Bugzilla is prone to a security-bypass vulnerability.
Successful exploits will allow authenticated attackers to modify the stat=
us of bug reports, which may aid in further attacks.
The following are vulnerable:
Bugzilla 3.1.1 through 3.2.3
Bugzilla 3.3.1 through 3.3.4
12. Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerab=
ility
BugTraq ID: 35601
Remote: No
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35601
Summary:
Microsoft Virtual PC and Virtual Server are prone to a privilege-escalati=
on vulnerability caused by an error in decoding privileged instructions.
Note that this issue affects only systems that do not use hardware-assist=
ed virtualization.
Successful exploits may allow local attackers to elevate privileges withi=
n a guest operating system.
13. Microsoft DirectX DirectShow Pointer Validation Remote Code Execution=
Vulnerability
BugTraq ID: 35600
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35600
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability that =
resides in the DirectShow component.
Successful exploits allow remote attackers to execute arbitrary code in t=
he context of the user running the application that uses DirectX. Failed =
exploit attempts will result in a denial-of-service condition.
14. Microsoft Publisher Object Handler Data Pointer Dereference Remote Co=
de Execution Vulnerability
BugTraq ID: 35599
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35599
Summary:
Microsoft Publisher is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing a victim to open a malicio=
us Publisher file.=20
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
15. Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified Remote M=
emory Corruption Vulnerability
BugTraq ID: 35585
Remote: Yes
Date Published: 2009-07-06
Relevant URL: http://www.securityfocus.com/bid/35585
Summary:
Microsoft Windows is prone to a remote memory-corruption vulnerability th=
at affects the Video Control ActiveX control.
An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted website.
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
Windows XP SP3 and Windows Server 2003 are vulnerable; other versions may=
also be affected.
16. Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Code Exec=
ution Vulnerability
BugTraq ID: 35558
Remote: Yes
Date Published: 2009-07-06
Relevant URL: http://www.securityfocus.com/bid/35558
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability that =
affects the TV Tuner library.
An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted website.
Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.
Windows XP SP3 and Windows Server 2003 are vulnerable; other versions may=
also be affected.
17. Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vuln=
erability
BugTraq ID: 35187
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35187
Summary:
Microsoft Windows is prone to a remotely exploitable integer-overflow vul=
nerability because it fails to properly bounds-check user-supplied input =
before copying it into an insufficiently sized memory buffer.=20
Remote attackers can exploit this issue to execute arbitrary machine code=
in the context of the vulnerable software on the targeted user's compute=
r.
18. Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnera=
bility
BugTraq ID: 35186
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35186
Summary:
Microsoft Windows is prone to a remotely exploitable heap-overflow vulner=
ability because the software fails to properly bounds-check user-supplied=
input before copying it into an insufficiently sized memory buffer.=20
Remote attackers can exploit this issue to execute arbitrary machine code=
in the context of the vulnerable software on the targeted user's compute=
r.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This issue is sponsored by Ironkey
INTRODUCING THE WORLD'S ONLY FIPS 140-2 LEVEL 3 VALIDATED USB FLASH DRIVE
=20
Designed to meet the needs of military, government and demanding enterpri=
se users, the IronKey. S200 series USB flash drives have passed the strin=
gent Security Level 3 tests for the FIPS 140-2 standard. A rugged, tamper=
-resistant and tamper-evident enclosure protects the critical components,=
while strong AES 256-bit hardware encryption and active malware defenses=
safeguard even the most sensitive data. Enterprise-class central managem=
ent capabilities also make it easy to enforce security policies on fleets=
of drives and even remotely destroy drives in the field.=20
=20
. Always-On AES 256-bit Hardware Encryption
=20
. FIPS 140-2 Level 3 Validated
=20
. Hardened Case.Waterproof Beyond MIL-STD-810F
=20
. Remote Management Software
=20
Research for the IronKey architecture was funded in part by the U.S. Depa=
rtment of Homeland Security. In addition, IronKey maintains a trusted sup=
ply chain: all research and development is performed in the USA, and all =
boards are built and all drives are assembled in secure facilities in the=
USA.
=20
IronKey Basic S200 drives will also be available in high-capacity 16GB mo=
dels.
https://www.ironkey.com/S200_Launch?ik_c=3Ds200_launch&ik_s=3Dsecurity_fo=
cus&ik_t=3Dnewsletter