SecurityFocus Microsoft Newsletter #448

[email protected] Tue, 14 Jul 2009 17:30:21 -0600
Newsgroups gmane.comp.security.news.microsoft
Message-ID <[email protected]>
SecurityFocus Microsoft Newsletter #448
----------------------------------------

This issue is sponsored by Ironkey

INTRODUCING THE WORLD'S ONLY FIPS 140-2 LEVEL 3 VALIDATED USB FLASH DRIVE
=20
Designed to meet the needs of military, government and demanding enterpri=
se users, the IronKey. S200 series USB flash drives have passed the strin=
gent Security Level 3 tests for the FIPS 140-2 standard. A rugged, tamper=
-resistant and tamper-evident enclosure protects the critical components,=
 while strong AES 256-bit hardware encryption and active malware defenses=
 safeguard even the most sensitive data. Enterprise-class central managem=
ent capabilities also make it easy to enforce security policies on fleets=
 of drives and even remotely destroy drives in the field.=20

Learn more at https://www.ironkey.com/S200_Launch


------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Hacker-Tool Law Still Does Little
       2. A Botnet by Any Other Name
II.  MICROSOFT VULNERABILITY SUMMARY
       1. Icarus '.icp' File Remote Stack Buffer Overflow Vulnerability
       2. Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Executi=
on Vulnerability
       3. LibTIFF Multiple Remote Integer Overflow Vulnerabilities
       4. Wyse Device Manager Unspecified Remote Buffer Overflow Vulnerab=
ility
       5. Microsoft Office Web Components ActiveX Control 'msDataSourceOb=
ject' Code Execution Vulnerability
       6. Pirch IRC Client Remote Buffer Overflow Vulnerability
       7. Microsoft ISA Server Radius OTP Authentication Bypass Vulnerabi=
lity=20
       8. Microsoft Internet Explorer 'AddFavorite' Method Denial of Serv=
ice Vulnerability
       9. Microsoft July 2009 Advance Notification Multiple Vulnerabiliti=
es
       10. Microsoft DirectX DirectShow Length Record Remote Code Executi=
on Vulnerability
       11. Bugzilla Bug Status Modification Security Bypass Vulnerability
       12. Microsoft Virtual PC and Virtual Server Privilege Escalation V=
ulnerability
       13. Microsoft DirectX DirectShow Pointer Validation Remote Code Ex=
ecution  Vulnerability
       14. Microsoft Publisher Object Handler Data Pointer Dereference Re=
mote Code Execution Vulnerability
       15. Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified R=
emote Memory Corruption Vulnerability
       16. Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Co=
de Execution Vulnerability
       17. Microsoft Windows Embedded OpenType Font Engine Integer Overfl=
ow Vulnerability
       18. Microsoft Windows Embedded OpenType Font Engine Heap Overflow =
Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Hacker-Tool Law Still Does Little
By Mark Rasch
On August 10, 2007, a new section of the German Penal code went into effe=
ct. The statute, intended to implement certain provisions of the Council =
of Europe Treaty on Cybercrime, could be interpreted to make the creation=
 or distribution of computer security software a criminal offense.=20
http://www.securityfocus.com/columnists/502

2. A Botnet by Any Other Name
By Gubter Ollmann
The news has been awash the last few weeks with fears over globe-spanning=
 botnets and their criminal intent: Conficker managed to hog the limeligh=
t for well over a month, and then came Finjan's disclosure of a previousl=
y unknown - and currently unnamed - botnet consisting of some 1.9 million=
 malicious agents.=20
http://www.securityfocus.com/columnists/501


II.  MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. Icarus '.icp' File Remote Stack Buffer Overflow Vulnerability
BugTraq ID: 35667
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35667
Summary:
Icarus is prone to a remote stack-based buffer-overflow vulnerability bec=
ause the application fails to perform adequate boundary checks on user-su=
pplied input.

Attackers may leverage this issue to execute arbitrary code in the contex=
t of the application. Failed attacks will cause denial-of-service conditi=
ons.

Icarus 2.0 is vulnerable; other versions may also be affected.

2. Mozilla Firefox 3.5 'Tracemonkey' Component Remote Code Execution Vuln=
erability
BugTraq ID: 35660
Remote: Yes
Date Published: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35660
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability.=20

Successful exploits may allow an attacker to execute arbitrary code in th=
e context of the user running the affected application. Failed attempts w=
ill likely result in denial-of-service conditions.

The issue affects Firefox 3.5; other versions may also be vulnerable.

NOTE: Remote code execution was confirmed in Firefox 3.5 running on Micro=
soft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP=
3.

3. LibTIFF Multiple Remote Integer Overflow Vulnerabilities
BugTraq ID: 35652
Remote: Yes
Date Published: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35652
Summary:
LibTIFF is prone to multiple remote integer-overflow vulnerabilities beca=
use it fails to perform adequate boundary checks on user-supplied data.

 An attacker can exploit these issues to execute arbitrary malicious code=
 in the context of a user running an application that uses the affected l=
ibrary. Failed exploit attempts will likely crash the application.

LibTIFF 3.8.2,  3.9, and 4.0 are vulnerable; other versions may also be a=
ffected.

4. Wyse Device Manager Unspecified Remote Buffer Overflow Vulnerability
BugTraq ID: 35649
Remote: Yes
Date Published: 2009-07-10
Relevant URL: http://www.securityfocus.com/bid/35649
Summary:
Wyse Device Manager is prone to a remote buffer-overflow vulnerability.

An attacker can exploit this issue to execute arbitrary code within the c=
ontext of the affected application. Failed exploit attempts will result i=
n a denial-of-service condition.

5. Microsoft Office Web Components ActiveX Control 'msDataSourceObject' C=
ode Execution Vulnerability
BugTraq ID: 35642
Remote: Yes
Date Published: 2009-07-13
Relevant URL: http://www.securityfocus.com/bid/35642
Summary:
Microsoft Office Web Components is prone to a remote code-execution vulne=
rability that affects the OWC Spreadsheet ActiveX control. The control is=
 identified by the following CLSIDs:

0002E541-0000-0000-C000-000000000046
0002E559-0000-0000-C000-000000000046

An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted site.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

6. Pirch IRC Client Remote Buffer Overflow Vulnerability
BugTraq ID: 35639
Remote: Yes
Date Published: 2009-07-12
Relevant URL: http://www.securityfocus.com/bid/35639
Summary:
Pirch IRC is prone to a remote buffer-overflow vulnerability because it f=
ails to bounds-check user-supplied data before copying it into an insuffi=
ciently sized buffer.

An attacker can exploit this issue by enticing an unsuspecting user into =
connecting to a malicious IRC server. Successful attacks will allow arbit=
rary code to run within the context of the affected application. Failed e=
xploit attempts will result in a denial-of-service condition.

Pirch IRC 98 is vulnerable; other versions may also be affected.

NOTE: The vulnerability may be related to the issue described in BID 5079=
. We will update the BID when more information emerges.

7. Microsoft ISA Server Radius OTP Authentication Bypass Vulnerability=20
BugTraq ID: 35631
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35631
Summary:
Microsoft ISA Server is prone to an authentication-bypass vulnerability.

An attacker with knowledge of a valid account name can exploit this issue=
 to bypass authentication and gain access to arbitrary resources within t=
he context of the selected account.

8. Microsoft Internet Explorer 'AddFavorite' Method Denial of Service Vul=
nerability
BugTraq ID: 35620
Remote: Yes
Date Published: 2009-07-09
Relevant URL: http://www.securityfocus.com/bid/35620
Summary:
Microsoft Internet Explorer is prone to a remote denial-of-service vulner=
ability.=20

Successful exploits can allow attackers to crash the affected browser, re=
sulting in denial-of-service conditions. Reports indicate that this issue=
 may be used to corrupt process memory and be leveraged to execute code, =
but this has not been confirmed.

Internet Explorer 7 and 8 are known to be vulnerable; other versions may =
be affected as well.

9. Microsoft July 2009 Advance Notification Multiple Vulnerabilities
BugTraq ID: 35617
Remote: Yes
Date Published: 2009-07-09
Relevant URL: http://www.securityfocus.com/bid/35617
Summary:
Microsoft has released advance notification that on July 14, 2009 the ven=
dor will be releasing six security bulletins covering multiple issues. Th=
e highest severity rating for these issues is 'Critical'.

These issues affect the following:

Windows
DirectX
Virtual PC
Virtual Server
ISA Server
Publisher

Successfully exploiting these issues may allow remote or local attackers =
to compromise affected computers.

We will create individual records to better document these issues when th=
e bulletins are released.

10. Microsoft DirectX DirectShow Length Record Remote Code Execution Vuln=
erability
BugTraq ID: 35616
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35616
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability that =
resides in the DirectShow component.

Successful exploits allow remote attackers to execute arbitrary code in t=
he context of the user running the application that uses DirectX. Failed =
exploit attempts will result in a denial-of-service condition.

11. Bugzilla Bug Status Modification Security Bypass Vulnerability
BugTraq ID: 35604
Remote: Yes
Date Published: 2009-07-08
Relevant URL: http://www.securityfocus.com/bid/35604
Summary:
Bugzilla is prone to a security-bypass vulnerability.

Successful exploits will allow authenticated attackers to modify the stat=
us of bug reports, which may aid in further attacks.

The following are vulnerable:

Bugzilla 3.1.1 through 3.2.3
Bugzilla 3.3.1 through 3.3.4

12. Microsoft Virtual PC and Virtual Server Privilege Escalation Vulnerab=
ility
BugTraq ID: 35601
Remote: No
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35601
Summary:
Microsoft Virtual PC and Virtual Server are prone to a privilege-escalati=
on vulnerability caused by an error in decoding privileged instructions.

Note that this issue affects only systems that do not use hardware-assist=
ed virtualization.

Successful exploits may allow local attackers to elevate privileges withi=
n a guest operating system.

13. Microsoft DirectX DirectShow Pointer Validation Remote Code Execution=
  Vulnerability
BugTraq ID: 35600
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35600
Summary:
Microsoft DirectX is prone to a remote code-execution vulnerability that =
resides in the DirectShow component.

Successful exploits allow remote attackers to execute arbitrary code in t=
he context of the user running the application that uses DirectX. Failed =
exploit attempts will result in a denial-of-service condition.

14. Microsoft Publisher Object Handler Data Pointer Dereference Remote Co=
de Execution Vulnerability
BugTraq ID: 35599
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35599
Summary:
Microsoft Publisher is prone to a remote code-execution vulnerability.

An attacker can exploit this issue by enticing a victim to open a malicio=
us Publisher file.=20

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

15. Microsoft Windows 'msvidctl.dll' ActiveX Control Unspecified Remote M=
emory Corruption Vulnerability
BugTraq ID: 35585
Remote: Yes
Date Published: 2009-07-06
Relevant URL: http://www.securityfocus.com/bid/35585
Summary:
Microsoft Windows is prone to a remote memory-corruption vulnerability th=
at affects the Video Control ActiveX control.

An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted website.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

Windows XP SP3 and Windows Server 2003 are vulnerable; other versions may=
 also be affected.

16. Microsoft Windows 'MPEG2TuneRequest' ActiveX Control Remote Code Exec=
ution Vulnerability
BugTraq ID: 35558
Remote: Yes
Date Published: 2009-07-06
Relevant URL: http://www.securityfocus.com/bid/35558
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability that =
affects the TV Tuner library.

An attacker could exploit this issue by enticing a victim to visit a mali=
ciously crafted website.

Successfully exploiting this issue would allow the attacker to execute ar=
bitrary code in the context of the currently logged-in user.

Windows XP SP3 and Windows Server 2003 are vulnerable; other versions may=
 also be affected.

17. Microsoft Windows Embedded OpenType Font Engine Integer Overflow Vuln=
erability
BugTraq ID: 35187
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35187
Summary:
Microsoft Windows is prone to a remotely exploitable integer-overflow vul=
nerability because it fails to properly bounds-check user-supplied input =
before copying it into an insufficiently sized memory buffer.=20

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of the vulnerable software on the targeted user's compute=
r.

18. Microsoft Windows Embedded OpenType Font Engine Heap Overflow Vulnera=
bility
BugTraq ID: 35186
Remote: Yes
Date Published: 2009-07-14
Relevant URL: http://www.securityfocus.com/bid/35186
Summary:
Microsoft Windows is prone to a remotely exploitable heap-overflow vulner=
ability because the software fails to properly bounds-check user-supplied=
 input before copying it into an insufficiently sized memory buffer.=20

Remote attackers can exploit this issue to execute arbitrary machine code=
 in the context of the vulnerable software on the targeted user's compute=
r.

III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Ironkey

INTRODUCING THE WORLD'S ONLY FIPS 140-2 LEVEL 3 VALIDATED USB FLASH DRIVE
=20
Designed to meet the needs of military, government and demanding enterpri=
se users, the IronKey. S200 series USB flash drives have passed the strin=
gent Security Level 3 tests for the FIPS 140-2 standard. A rugged, tamper=
-resistant and tamper-evident enclosure protects the critical components,=
 while strong AES 256-bit hardware encryption and active malware defenses=
 safeguard even the most sensitive data. Enterprise-class central managem=
ent capabilities also make it easy to enforce security policies on fleets=
 of drives and even remotely destroy drives in the field.=20
=20
.	Always-On AES 256-bit Hardware Encryption
=20
.	FIPS 140-2 Level 3 Validated
=20
.	Hardened Case.Waterproof Beyond MIL-STD-810F
=20
.	Remote Management Software
=20
Research for the IronKey architecture was funded in part by the U.S. Depa=
rtment of Homeland Security. In addition, IronKey maintains a trusted sup=
ply chain: all research and development is performed in the USA, and all =
boards are built and all drives are assembled in secure facilities in the=
 USA.
=20
IronKey Basic S200 drives will also be available in high-capacity 16GB mo=
dels.

https://www.ironkey.com/S200_Launch?ik_c=3Ds200_launch&ik_s=3Dsecurity_fo=
cus&ik_t=3Dnewsletter