<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-415</id>
	<title>Nabble - Security - Microsoft</title>
	<updated>2008-10-02T09:50:59Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/Security---Microsoft-f415.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Security---Microsoft-f415.html" />
	<subtitle type="html"></subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-19784122</id>
	<title>SecurityFocus Microsoft Newsletter #414</title>
	<published>2008-10-02T09:50:59Z</published>
	<updated>2008-10-02T09:50:59Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
	<content type="html">SecurityFocus Microsoft Newsletter #414
&lt;br&gt;----------------------------------------
&lt;br&gt;&lt;br&gt;This issue is sponsored by HP:
&lt;br&gt;&lt;br&gt;Download a FREE trial of HP WebInspect
&lt;br&gt;Application attacks are growing more prevalent. New attacks are in the news each day. Now it's time for you to assess your applications and start detecting and removing vulnerabilities. 
&lt;br&gt;HP can help, with a full suite of application security solutions. Get started today with a complimentary trial download that uses an HP test application. Thoroughly analyze today's complex web applications in a runtime environment with fast scanning capabilities, broad assessment coverage and accurate web application scanning results. 
&lt;br&gt;Download WebInspect now:&lt;a href=&quot;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SECURITY BLOGS
&lt;br&gt;SecurityFocus has selected a few syndicated sources that stand out as conveying topics of interest for our community. We are proud to offer content from Matasano at this time and will be adding more in the coming weeks.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/blogs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/blogs&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------
&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.Blaming the Good Samaritan
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.The Boston Trio and the MBTA
&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. ESET SysInspector 'esiadrv.sys' Local Privilege Escalation Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. WinZip 'gdiplus.dll' Microsoft Module Unspecified Security Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. Marshal MailMarshal SMTP Spam Quarantine Management Multiple HTML Injection Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4. Wireshark Packet Capture File Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5. Microsoft GDI+ 'GDIPLUS.dll' ICO File Divide-By-Zero Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6. ZoneAlarm HTTP Proxy Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7. Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8. DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9. Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10. phpMyAdmin Cross Site Scripting Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;11. DataSpade 'index.asp' Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12. Foxmail Email Client 'mailto' Buffer Overflow Vulnerability
&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. SecurityFocus Microsoft Newsletter #413
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;---------------------
&lt;br&gt;1.Blaming the Good Samaritan
&lt;br&gt;By Houston Carr
&lt;br&gt;In the early 90's, I attended an academic conference in Hawaii. At one presentation, a colleague from the University of California at Berkeley whom I'll refer to as &amp;quot;the supervisor,&amp;quot; told a story of young hackers, who he referred to as the Urchins
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/481&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/481&lt;/a&gt;&lt;br&gt;&lt;br&gt;2.The Boston Trio and the MBTA
&lt;br&gt;By Mark Rasch
&lt;br&gt;The annual DEFCON conference in Las Vegas in early August got a bit more interesting than usual when three graduate students from the Massachusetts Institute of Technology were enjoined from giving a presentation by a Court in Boston.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/480&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/480&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;------------------------------------
&lt;br&gt;1. ESET SysInspector 'esiadrv.sys' Local Privilege Escalation Vulnerability
&lt;br&gt;BugTraq ID: 31521
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-10-01
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31521&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31521&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;ESET SysInspector is prone to a local privilege-escalation vulnerability that occurs in the 'esiadrv.sys' driver. 
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code with kernel-level privileges on a Microsoft Windows host operating system. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;ESET SysInspector 1.1.1.0 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;2. WinZip 'gdiplus.dll' Microsoft Module Unspecified Security Vulnerability
&lt;br&gt;BugTraq ID: 31485
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31485&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31485&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;WinZip is prone to an unspecified vulnerability that stems from an error in the Microsoft 'gdiplus.dll' component included with the application.
&lt;br&gt;&lt;br&gt;NOTE: The issues described in this BID may be related to one or more of the issues described in the Microsoft MS08-052 security bulletin. 
&lt;br&gt;&lt;br&gt;Reports indicate that this issue may allow attackers to execute arbitrary code in the context of the affected application, but Symantec has not confirmed this information.
&lt;br&gt;&lt;br&gt;This issue affects WinZip 11.x (prior to 11.2 SR-1) on Windows 2000 systems.
&lt;br&gt;&lt;br&gt;3. Marshal MailMarshal SMTP Spam Quarantine Management Multiple HTML Injection Vulnerabilities
&lt;br&gt;BugTraq ID: 31483
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31483&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31483&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Marshal MailMarshal SMTP Spam Quarantine Management component is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
&lt;br&gt;&lt;br&gt;Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
&lt;br&gt;&lt;br&gt;Reportedly, the attacker may be able to further exploit these issues to install arbitrary files on a victim's computer.
&lt;br&gt;&lt;br&gt;These issues affect MailMarshal SMTP 6.0 up to and including 6.3.
&lt;br&gt;&lt;br&gt;4. Wireshark Packet Capture File Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31468
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-29
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31468&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31468&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Wireshark is prone to a denial-of-service vulnerability.
&lt;br&gt;&lt;br&gt;Exploiting this issue may allow attackers to cause crashes and deny service to legitimate users of the application. 
&lt;br&gt;&lt;br&gt;Wireshark 1.0.3 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;5. Microsoft GDI+ 'GDIPLUS.dll' ICO File Divide-By-Zero Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31432
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31432&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31432&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a denial-of-service vulnerability when processing a malformed ICO file. 
&lt;br&gt;&lt;br&gt;A remote attacker can exploit this issue to crash the affected application, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;6. ZoneAlarm HTTP Proxy Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31431
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31431&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31431&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;ZoneAlarm Internet Security Suite is prone to a remote denial-of-service vulnerability that occurs in the TrueVector component when connecting to a malicious HTTP proxy.
&lt;br&gt;&lt;br&gt;ZoneAlarm Internet Security Suite 8.0.020 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;7. Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31420
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31420&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31420&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows Mobile is prone to a denial-of-service vulnerability because it fails to adequately validate user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to crash a device running Windows Mobile, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;Windows Mobile 6.0 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;8. DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31418
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31418&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31418&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;DATAC RealWin SCADA server is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code in the context of the affected application. &amp;nbsp;This may facilitate the complete compromise of affected computers. &amp;nbsp;Failed exploit attempts may result in a denial-of-service condition. &amp;nbsp; 
&lt;br&gt;&lt;br&gt;RealWin SCADA server 2.0 is affected; other versions may also be vulnerable.
&lt;br&gt;&lt;br&gt;9. Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31399
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31399&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31399&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;WordPad is prone to a remote denial-of-service vulnerability. 
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue by enticing an unsuspecting victim to open a specially crafted '.doc' file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will cause the application to crash, denying service to legitimate users. Attackers may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;10. phpMyAdmin Cross Site Scripting Vulnerability
&lt;br&gt;BugTraq ID: 31327
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-23
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31327&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31327&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
&lt;br&gt;&lt;br&gt;An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
&lt;br&gt;&lt;br&gt;Versions prior to phpMyAdmin 2.11.9.2 are vulnerable.
&lt;br&gt;&lt;br&gt;11. DataSpade 'index.asp' Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;BugTraq ID: 31317
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-23
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31317&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31317&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;DataSpade is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
&lt;br&gt;&lt;br&gt;An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
&lt;br&gt;&lt;br&gt;DataSpade 1.0 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;12. Foxmail Email Client 'mailto' Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31294
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-22
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31294&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31294&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Foxmail Email Client is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will allow an attacker to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. 
&lt;br&gt;&lt;br&gt;Foxmail Email Client 6.5 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;---------------------------------
&lt;br&gt;1. SecurityFocus Microsoft Newsletter #413
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/88/496752&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/archive/88/496752&lt;/a&gt;&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;-----------------------------
&lt;br&gt;To unsubscribe send an e-mail message to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19784122&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ms-secnews-unsubscribe@...&lt;/a&gt; from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit &lt;a href=&quot;http://www.securityfocus.com/newsletters&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/newsletters&lt;/a&gt;&amp;nbsp;and unsubscribe via the website.
&lt;br&gt;&lt;br&gt;If your email address has changed email &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19784122&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listadmin@...&lt;/a&gt; and ask to be manually removed.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;------------------------
&lt;br&gt;This issue is sponsored by HP:
&lt;br&gt;&lt;br&gt;Download a FREE trial of HP WebInspect
&lt;br&gt;Application attacks are growing more prevalent. New attacks are in the news each day. Now it's time for you to assess your applications and start detecting and removing vulnerabilities. 
&lt;br&gt;HP can help, with a full suite of application security solutions. Get started today with a complimentary trial download that uses an HP test application. Thoroughly analyze today's complex web applications in a runtime environment with fast scanning capabilities, broad assessment coverage and accurate web application scanning results. 
&lt;br&gt;Download WebInspect now:&lt;a href=&quot;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SecurityFocus-Microsoft-Newsletter--414-tp19784122p19784122.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19679433</id>
	<title>SecurityFocus Microsoft Newsletter #413</title>
	<published>2008-09-25T15:12:33Z</published>
	<updated>2008-09-25T15:12:33Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
	<content type="html">&lt;br&gt;SecurityFocus Microsoft Newsletter #413
&lt;br&gt;----------------------------------------
&lt;br&gt;&lt;br&gt;Download a FREE trial of HP WebInspect
&lt;br&gt;&lt;br&gt;Application attacks are growing more prevalent. New attacks are in the news each day. Now it's time for you to assess your applications and start detecting and removing vulnerabilities. 
&lt;br&gt;HP can help, with a full suite of application security solutions. &amp;nbsp;Get started today with a complimentary trial download that uses an HP test application. Thoroughly analyze today's complex web applications in a runtime environment with fast scanning capabilities, broad assessment coverage and accurate web application scanning results. 
&lt;br&gt;Download WebInspect now: &lt;a href=&quot;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SECURITY BLOGS
&lt;br&gt;SecurityFocus has selected a few syndicated sources that stand out as conveying topics of interest for our community. We are proud to offer content from Matasano at this time and will be adding more in the coming weeks.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/blogs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/blogs&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------
&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.The Boston Trio and the MBTA
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.From Physics to Security
&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. K-Lite Mega Codec Pack 'vsfilter.dll' Denial Of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. phpMyAdmin Cross Site Scripting Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4. DataSpade 'index.asp' Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5. Foxmail Email Client 'mailto' Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6. DESlock+ Local Buffer Overflow and Multiple Denial of Service Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7. Kantan WEB Server Unspecified Directory Traversal Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8. Kantan WEB Server Unspecified Cross Site Scripting Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9. Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10. Acritum Femitter Server Information Disclosure and Denial of Service Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;11. Microsoft Internet Explorer Malfromed PNG File Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12. Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;13. Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;14. Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service Vulnerability
&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;---------------------
&lt;br&gt;1.The Boston Trio and the MBTA
&lt;br&gt;By Mark Rasch
&lt;br&gt;The annual DEFCON conference in Las Vegas in early August got a bit more interesting than usual when three graduate students from the Massachusetts Institute of Technology were enjoined from giving a presentation by a Court in Boston.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/480&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/480&lt;/a&gt;&lt;br&gt;&lt;br&gt;2.From Physics to Security
&lt;br&gt;By Federico Biancuzzi
&lt;br&gt;Wietse Venema started out as a physicist, but became interested in the security of the programs he wrote to control his physics experiments. He went on to create several well-known network and security tools, including the Security Administrator's Tool for Analyzing Networks (SATAN) and The Coroner's Toolkit with Dan Farmer. He is also the creator of the popular MTA Postfix and TCP Wrapper. 
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/479&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/479&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;------------------------------------
&lt;br&gt;1. K-Lite Mega Codec Pack 'vsfilter.dll' Denial Of Service Vulnerability
&lt;br&gt;BugTraq ID: 31400
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31400&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31400&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;K-Lite Mega Codec pack is prone to a denial-of-service vulnerability. The problem occurs when the 'vsfilter.dll' library is installed on the affected computer.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue to cause Windows Explorer to crash, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;2. Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31399
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31399&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31399&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;WordPad is prone to a remote denial-of-service vulnerability. 
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue by enticing an unsuspecting victim to open a specially crafted .doc file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will cause the application to crash, denying service to legitimate users. Arbitrary code execution may also be possible; this has not been confirmed.
&lt;br&gt;&lt;br&gt;3. phpMyAdmin Cross Site Scripting Vulnerability
&lt;br&gt;BugTraq ID: 31327
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-23
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31327&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31327&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;phpMyAdmin is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
&lt;br&gt;&lt;br&gt;An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
&lt;br&gt;&lt;br&gt;Versions prior to phpMyAdmin 2.11.9.2 are vulnerable.
&lt;br&gt;&lt;br&gt;4. DataSpade 'index.asp' Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;BugTraq ID: 31317
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-23
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31317&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31317&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;DataSpade is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
&lt;br&gt;&lt;br&gt;An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
&lt;br&gt;&lt;br&gt;DataSpade 1.0 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;5. Foxmail Email Client 'mailto' Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31294
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-22
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31294&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31294&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Foxmail Email Client is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will allow an attacker to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. 
&lt;br&gt;&lt;br&gt;Foxmail Email Client 6.5 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;6. DESlock+ Local Buffer Overflow and Multiple Denial of Service Vulnerabilities
&lt;br&gt;BugTraq ID: 31273
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-09-20
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31273&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31273&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;DESlock+ is prone to multiple local vulnerabilities, including a buffer-overflow issue and multiple denial-of-service issues.
&lt;br&gt;&lt;br&gt;Local attackers can exploit these issues to execute arbitrary code with SYSTEM-level privileges or cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;These issues affect DESlock+ 3.2.7 and prior versions.
&lt;br&gt;&lt;br&gt;7. Kantan WEB Server Unspecified Directory Traversal Vulnerability
&lt;br&gt;BugTraq ID: 31245
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-18
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31245&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31245&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Kantan WEB Server is prone to an unspecified directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input. 
&lt;br&gt;&lt;br&gt;Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
&lt;br&gt;&lt;br&gt;Versions prior to Kantan WEB Server 1.9 are vulnerable.
&lt;br&gt;&lt;br&gt;8. Kantan WEB Server Unspecified Cross Site Scripting Vulnerability
&lt;br&gt;BugTraq ID: 31244
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-18
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31244&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31244&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Kantan WEB Server is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. 
&lt;br&gt;&lt;br&gt;An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
&lt;br&gt;&lt;br&gt;Versions prior to Kantan WEB Server 1.9 are vulnerable.
&lt;br&gt;&lt;br&gt;9. Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
&lt;br&gt;BugTraq ID: 31227
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-17
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31227&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31227&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Data Dynamics ActiveReports ActiveX control is prone to multiple insecure-method vulnerabilities caused by design errors.
&lt;br&gt;&lt;br&gt;An attacker can exploit these issues to overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow attackers to cause denial-of-service conditions; other consequences are possible. 
&lt;br&gt;&lt;br&gt;These issues affect Data Dynamics ActiveReports Professional Edition Build 2.5.0.1314 ('ARView2.ocx' version 2.5.0.1314); other versions may also be affected.
&lt;br&gt;&lt;br&gt;10. Acritum Femitter Server Information Disclosure and Denial of Service Vulnerabilities
&lt;br&gt;BugTraq ID: 31226
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-17
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31226&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31226&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Acritum Femitter Server is prone to an information-disclosure vulnerability and a denial-of-service vulnerability.
&lt;br&gt;&lt;br&gt;Successfully exploiting these issues may allow an attacker to obtain sensitive information or cause the affected application to crash, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;Femitter Server 1.03 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;11. Microsoft Internet Explorer Malfromed PNG File Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31215
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-17
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31215&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31215&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Internet Explorer is prone to a remote denial-of-service vulnerability. 
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue by enticing an unsuspecting victim to view a web page embedded with a malicious PNG file. 
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will cause the application to stop responding, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;Microsoft Internet Explorer 7 and 8 Beta 1 are vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;12. Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31208
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-16
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31208&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31208&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Adobe Illustrator is prone to a remote code-execution vulnerability. 
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious AI file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application. 
&lt;br&gt;&lt;br&gt;This issue affects only Adobe Illustrator CS2 for Macintosh.
&lt;br&gt;&lt;br&gt;13. Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31204
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-16
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31204&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31204&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Acresso FLEXnet Connect is prone to a remote code-execution vulnerability because it fails to adequately verify the authenticity of files obtained from update servers. The product has been formerly available as Macrovision FLEXnet Connect and as InstallShield Update Service.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue by performing man-in-the-middle attacks to have the client download and execute a malicious file hosted on an attacker-controlled computer. Other attacks may also be possible.
&lt;br&gt;&lt;br&gt;Acresso FLEXnet Connect is vulnerable. Additional products that use the FLEXnet functionality may also be vulnerable.
&lt;br&gt;&lt;br&gt;14. Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service Vulnerability
&lt;br&gt;BugTraq ID: 31179
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-15
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31179&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31179&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows is prone to a remote denial-of-service vulnerability because it fails to adequately handle specially crafted SMB packets.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue to cause an affected computer to stop responding, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code with SYSTEM-level privileges, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;---------------------------------
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;-----------------------------
&lt;br&gt;To unsubscribe send an e-mail message to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19679433&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ms-secnews-unsubscribe@...&lt;/a&gt; from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit &lt;a href=&quot;http://www.securityfocus.com/newsletters&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/newsletters&lt;/a&gt;&amp;nbsp;and unsubscribe via the website.
&lt;br&gt;&lt;br&gt;If your email address has changed email &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19679433&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listadmin@...&lt;/a&gt; and ask to be manually removed.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;------------------------
&lt;br&gt;Download a FREE trial of HP WebInspect
&lt;br&gt;&lt;br&gt;Application attacks are growing more prevalent. New attacks are in the news each day. Now it's time for you to assess your applications and start detecting and removing vulnerabilities. 
&lt;br&gt;HP can help, with a full suite of application security solutions. &amp;nbsp;Get started today with a complimentary trial download that uses an HP test application. Thoroughly analyze today's complex web applications in a runtime environment with fast scanning capabilities, broad assessment coverage and accurate web application scanning results. 
&lt;br&gt;Download WebInspect now: &lt;a href=&quot;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://h10078.www1.hp.com/cda/hpdc/navigation.do?action=downloadBinStart&amp;zn=bto&amp;cp=54_4012_100__&amp;caid=14563&amp;jumpid=ex_r11374_us/en/large/tsg/WebInspect_Eval_Security_Focus/3-1QN6MIF_3-UTM2ZJ/20080920&amp;origin_id=3-1QN6MIF&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SecurityFocus-Microsoft-Newsletter--413-tp19679433p19679433.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19542629</id>
	<title>SecurityFocus Microsoft Newsletter #412</title>
	<published>2008-09-17T15:33:07Z</published>
	<updated>2008-09-17T15:33:07Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
	<content type="html">SecurityFocus Microsoft Newsletter #412
&lt;br&gt;----------------------------------------
&lt;br&gt;&lt;br&gt;This issue is sponsored by Sponsored by Ironkey: The World's Most Secure Flash Drive
&lt;br&gt;&lt;br&gt;IronKey flash dives lock down your most sensitive data using today's most advanced security technology. 
&lt;br&gt;IronKey uses military-grade AES CBC-mode hardware encryption that cannot be disabled by malware or an intruder and provides rugged and waterproof protection to safeguard your data.
&lt;br&gt;&lt;a href=&quot;https://www.ironkey.com/forenterprise2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.ironkey.com/forenterprise2&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SECURITY BLOGS
&lt;br&gt;SecurityFocus has selected a few syndicated sources that stand out as conveying topics of interest for our community. We are proud to offer content from Matasano at this time and will be adding more in the coming weeks.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/blogs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/blogs&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------
&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.SATAN'S Helper
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.Get Off My Cloud
&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. Microsoft Internet Explorer Malfromed PNG File Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4. Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5. Personal FTP Server 'RETR' Command Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6. Baidu Hi 'CSTransfer.dll' Remote Stack Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7. Avant Browser JavaScript Engine Integer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8. RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9. ZoneAlarm Security Suite AntiVirus Directory Path Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10. Maxthon Browser Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;11. Apple iTunes Misleading Firewall Warning Weakness
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12. Apple iTunes Third Party Driver Local Privilege Escalation Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;13. Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;14. Microsoft Windows Image Acquisition Logger ActiveX Control Arbitrary File Overwrite Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;15. Microsoft Office OneNote URL Handler Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;16. Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;17. Microsoft Organization Chart Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;18. Microsoft GDI+ BMP Integer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;19. Microsoft GDI+ WMF Image File Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;20. Microsoft GDI+ GIF File Parsing Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;21. Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;22. Microsoft GDI+ VML Heap-Based Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;23. Microsoft Windows Media Player SSPL File Sample Rate Remote Code-Execution Vulnerability
&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. SecurityFocus Microsoft Newsletter #411
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;---------------------
&lt;br&gt;1.SATAN's Helper
&lt;br&gt;By Federico Biancuzzi
&lt;br&gt;SecurityFocus contributor Federico Biancuzzi chatted up Venema to talk about software security, how to improve the code quality, what solutions we might have to fight spam successfully, the principle of least privilege, and the philosophy behind the design of Postfix. 
&lt;br&gt;Venema is currently a researcher at IBM's T.J. Watson Research Center
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/479&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/479&lt;/a&gt;&lt;br&gt;&lt;br&gt;2.Get Off My Cloud
&lt;br&gt;By Mark Rasch
&lt;br&gt;One of the features of Apple's device that appeals to me is the new MobileMe service, where you can &amp;quot;access and manage your email, contacts, calendar, photos, and files at me.com,&amp;quot; according to Apple. 
&lt;br&gt;More companies, among them Microsoft and Google, already allow people to store information and use common services online -- or &amp;quot;in the cloud&amp;quot; -- leading analysts to refer to the entire trend as &amp;quot;cloud computing.&amp;quot;
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/478&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/478&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;------------------------------------
&lt;br&gt;1. Microsoft Internet Explorer Malfromed PNG File Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31215
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-17
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31215&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31215&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Internet Explorer is prone to a remote denial-of-service vulnerability. 
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue by enticing an unsuspecting victim to view a web page embedded with a malicious PNG file. 
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will cause the application to stop responding, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;Microsoft Internet Explorer 7 and 8 Beta 1 are vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;2. Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31208
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-16
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31208&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31208&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Adobe Illustrator is prone to a remote code-execution vulnerability. 
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious AI file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application. 
&lt;br&gt;&lt;br&gt;This issue affects only Adobe Illustrator CS2 for Macintosh.
&lt;br&gt;&lt;br&gt;3. Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31204
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-16
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31204&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31204&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Acresso FLEXnet Connect is prone to a remote code-execution vulnerability because it fails to adequately verify the authenticity of files obtained from update servers. The product has been formerly available as Macrovision FLEXnet Connect and as InstallShield Update Service.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue by performing man-in-the-middle attacks to have the client download and execute a malicious file hosted on an attacker-controlled computer. Other attacks may also be possible.
&lt;br&gt;&lt;br&gt;Acresso FLEXnet Connect is vulnerable. Additional products that use the FLEXnet functionality may also be vulnerable.
&lt;br&gt;&lt;br&gt;4. Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service Vulnerability
&lt;br&gt;BugTraq ID: 31179
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-15
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31179&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31179&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows is prone to a remote denial-of-service vulnerability because it fails to adequately handle specially crafted SMB packets.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue to cause an affected computer to stop responding, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code with SYSTEM-level privileges, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;5. Personal FTP Server 'RETR' Command Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31173
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-14
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31173&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31173&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Personal FTP Server is prone to a remote denial-of-service vulnerability because the application fails to handle exceptional conditions. 
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would cause the affected application to crash, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;Personal FTP Server 6.0f is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;6. Baidu Hi 'CSTransfer.dll' Remote Stack Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31162
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-13
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31162&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31162&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Baidu Hi is prone to a remote stack-based buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer. 
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial of service.
&lt;br&gt;&lt;br&gt;7. Avant Browser JavaScript Engine Integer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31155
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-12
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31155&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31155&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Avant Browser is prone to an integer-overflow vulnerability that occurs in the JavaScript engine.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious site. 
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue may allow attackers to crash the affected application, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;Avant Browser 11.7 Build 9 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;NOTE: This vulnerability may be related to the issue described in BID 14917 (Mozilla Browser/Firefox JavaScript Engine Integer Overflow Vulnerability).
&lt;br&gt;&lt;br&gt;8. RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31129
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-11
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31129&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31129&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft SQL Server 'sqlvdir.dll' ActiveX Control is prone to a buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
&lt;br&gt;&lt;br&gt;&amp;nbsp;This control is included with Microsoft SQL Server 2000; other versions may also be affected.
&lt;br&gt;&lt;br&gt;NOTE: This BID is being retired because the issue is not exploitable. The ActiveX control is not marked 'Safe for Scripting'.
&lt;br&gt;&lt;br&gt;9. ZoneAlarm Security Suite AntiVirus Directory Path Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31124
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-11
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31124&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31124&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;ZoneAlarm Security Suite is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input when performing virus scans on long directory paths.
&lt;br&gt;&lt;br&gt;Remote attackers may leverage this issue to execute arbitrary code with SYSTEM-level privileges and gain complete access to the vulnerable computer. Failed attacks will cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;This issue affects ZoneAlarm Security Suite 7.0.483.000; other versions may also be affected.
&lt;br&gt;&lt;br&gt;10. Maxthon Browser Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31098
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31098&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31098&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Maxthon Browser is prone to a denial-of-service vulnerability. 
&lt;br&gt;&lt;br&gt;An attacker may exploit this issue by enticing victims into opening a maliciously crafted webpage.
&lt;br&gt;&lt;br&gt;&amp;nbsp;Successfully exploiting this issue will allow the attacker to crash the application, denying service to legitimate users. 
&lt;br&gt;&lt;br&gt;This issue affects Maxthon Browser 2.1.4.443; other versions may also be affected.
&lt;br&gt;&lt;br&gt;11. Apple iTunes Misleading Firewall Warning Weakness
&lt;br&gt;BugTraq ID: 31090
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31090&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31090&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Apple iTunes is prone to a weakness caused by a misleading firewall warning that conveys erroneous information to users.
&lt;br&gt;&lt;br&gt;This issue may lead to a false sense of security, potentially aiding in network-based attacks.
&lt;br&gt;&lt;br&gt;Versions prior to Apple iTunes 8.0 are vulnerable to this issue.
&lt;br&gt;&lt;br&gt;12. Apple iTunes Third Party Driver Local Privilege Escalation Vulnerability
&lt;br&gt;BugTraq ID: 31089
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31089&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31089&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Apple iTunes is prone to a local privilege-escalation vulnerability due to an integer-overflow issue. 
&lt;br&gt;&lt;br&gt;Local attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
&lt;br&gt;&lt;br&gt;This issue affects versions prior to iTunes 8.0 for Microsoft Windows XP and Microsoft Windows Vista.
&lt;br&gt;&lt;br&gt;13. Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities
&lt;br&gt;BugTraq ID: 31086
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31086&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31086&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Apple QuickTime is prone to multiple remote vulnerabilities that may allow remote attackers to execute arbitrary code and carry out denial-of-service attacks.
&lt;br&gt;&lt;br&gt;These issues arise when the application handles specially crafted PICT image files, movies, and QTVR movies. Successful exploits may allow attackers to gain remote unauthorized access in the context of a vulnerable user and to trigger a denial-of-service condition.
&lt;br&gt;&lt;br&gt;Versions prior to QuickTime 7.5.5 are affected.
&lt;br&gt;&lt;br&gt;14. Microsoft Windows Image Acquisition Logger ActiveX Control Arbitrary File Overwrite Vulnerability
&lt;br&gt;BugTraq ID: 31069
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-08
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31069&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31069&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows Image Acquisition Logger ActiveX control is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content. The issue occurs because the control fails to sanitize user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to overwrite files with attacker-supplied data, which will aid in further attacks.
&lt;br&gt;&lt;br&gt;15. Microsoft Office OneNote URL Handler Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31067
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31067&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31067&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Office OneNote is prone to a remote code-execution vulnerability.
&lt;br&gt;&lt;br&gt;An attacker could exploit this issue by enticing a victim to follow maliciously crafted URIs.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;16. Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31065
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31065&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31065&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;The Microsoft Windows Media Encoder 9 ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;17. Microsoft Organization Chart Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31059
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-08
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31059&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31059&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Organization Chart is prone to a remote code-execution vulnerability because of a memory-access violation.
&lt;br&gt;&lt;br&gt;Remote attackers can exploit this issue by enticing victims into opening a maliciously crafted Organization Chart document.
&lt;br&gt;&lt;br&gt;Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
&lt;br&gt;&lt;br&gt;Microsoft Organization Chart 2.00,19 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;18. Microsoft GDI+ BMP Integer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31022
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31022&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31022&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to an integer-overflow vulnerability.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue by enticing unsuspecting users to view a malicious BMP file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue allows remote attackers to corrupt memory and execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;19. Microsoft GDI+ WMF Image File Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31021
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31021&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31021&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a buffer-overflow vulnerability because the vector graphics linked library improperly allocates memory when parsing WMF image files.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow an attacker to corrupt memory and execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;20. Microsoft GDI+ GIF File Parsing Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31020
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31020&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31020&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a remote code-execution vulnerability because the vector graphics link library improperly parses GIF image files.
&lt;br&gt;&lt;br&gt;An attacker could exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts may crash applications that use the library.
&lt;br&gt;&lt;br&gt;21. Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability
&lt;br&gt;BugTraq ID: 31019
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31019&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31019&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a remote memory-corruption vulnerability that occurs when an application that uses the library tries to process a specially crafted EMF (Enhanced Metafile) image file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;22. Microsoft GDI+ VML Heap-Based Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31018
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31018&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31018&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a heap-based buffer-overflow vulnerability because the vector graphics link library improperly processes gradient sizes.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow an attacker to corrupt heap memory and execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;23. Microsoft Windows Media Player SSPL File Sample Rate Remote Code-Execution Vulnerability
&lt;br&gt;BugTraq ID: 30550
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30550&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30550&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows Media Player is prone to a remote code-execution vulnerability.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;NOTE: Supported editions of Windows Server 2008 are not affected if installed using the Server Core installation option.
&lt;br&gt;&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;---------------------------------
&lt;br&gt;1. SecurityFocus Microsoft Newsletter #411
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/88/496270&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/archive/88/496270&lt;/a&gt;&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;-----------------------------
&lt;br&gt;To unsubscribe send an e-mail message to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19542629&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ms-secnews-unsubscribe@...&lt;/a&gt; from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit &lt;a href=&quot;http://www.securityfocus.com/newsletters&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/newsletters&lt;/a&gt;&amp;nbsp;and unsubscribe via the website.
&lt;br&gt;&lt;br&gt;If your email address has changed email &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19542629&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listadmin@...&lt;/a&gt; and ask to be manually removed.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;------------------------
&lt;br&gt;This issue is sponsored by Sponsored by Ironkey: The World's Most Secure Flash Drive
&lt;br&gt;&lt;br&gt;IronKey flash dives lock down your most sensitive data using today's most advanced security technology. 
&lt;br&gt;IronKey uses military-grade AES CBC-mode hardware encryption that cannot be disabled by malware or an intruder and provides rugged and waterproof protection to safeguard your data.
&lt;br&gt;&lt;a href=&quot;https://www.ironkey.com/forenterprise2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.ironkey.com/forenterprise2&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SecurityFocus-Microsoft-Newsletter--412-tp19542629p19542629.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19458252</id>
	<title>SecurityFocus Microsoft Newsletter #411</title>
	<published>2008-09-12T08:09:20Z</published>
	<updated>2008-09-12T08:09:20Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
	<content type="html">&lt;br&gt;SecurityFocus Microsoft Newsletter #411
&lt;br&gt;----------------------------------------
&lt;br&gt;&lt;br&gt;This issue is sponsored by Sponsored by Ironkey: The World's Most Secure Flash Drive
&lt;br&gt;&lt;br&gt;IronKey flash dives lock down your most sensitive data using today's most advanced security technology.
&lt;br&gt;IronKey uses military-grade AES CBC-mode hardware encryption that cannot be disabled by malware or an intruder and provides rugged and waterproof protection to safeguard your data.
&lt;br&gt;&lt;a href=&quot;https://www.iroky.com/forenterprise2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.iroky.com/forenterprise2&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SECURITY BLOGS
&lt;br&gt;SecurityFocus has selected a few syndicated sources that stand out as conveying topics of interest for our community. We are proud to offer content from Matasano at this time and will be adding more in the coming weeks.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/blogs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/blogs&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------
&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.Get Off My Cloud
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.An Astonishing Collaboration
&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1. Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2. ZoneAlarm Security Suite AntiVirus Directory Path Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3. Maxthon Browser Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4. Apple iTunes Misleading Firewall Warning Weakness
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 5. Apple iTunes Third Party Driver Local Privilege Escalation Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6. Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7. Microsoft Windows Image Acquisition Logger ActiveX Control Arbitrary File Overwrite Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 8. Microsoft Office OneNote URL Handler Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9. Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10. Microsoft Organization Chart Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11. IBM DB2 Universal Database Server 8.2 Prior To Fixpak 17 Multiple Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 12. Microsoft GDI+ BMP Integer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 13. Microsoft GDI+ WMF Image File Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14. Microsoft GDI+ GIF File Parsing Remote Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 15. Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 16. Microsoft GDI+ VML Heap-Based Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 17. Microsoft September 2008 Advance Notification Multiple Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 18. Wireshark 1.0.2 Multiple Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 19. RETIRED: Moodle Multiple Remote File Include Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 20. Open-FTPD &amp;nbsp;Multiple Command Remote Denial of Service Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 21. @Mail and @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 22. Softalk Mail Server 'APPEND' Command Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 23. Microsoft Windows Media Player SSPL File Sample Rate Remote Code-Execution Vulnerability
&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;---------------------
&lt;br&gt;1.Get Off My Cloud
&lt;br&gt;By Mark Rasch
&lt;br&gt;One of the features of Apple's device that appeals to me is the new MobileMe service, where you can &amp;quot;access and manage your email, contacts, calendar, photos, and files at me.com,&amp;quot; according to Apple.
&lt;br&gt;More companies, among them Microsoft and Google, already allow people to store information and use common services online -- or &amp;quot;in the cloud&amp;quot; -- leading analysts to refer to the entire trend as &amp;quot;cloud computing.&amp;quot;
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/478&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/478&lt;/a&gt;&lt;br&gt;&lt;br&gt;2.An Astonishing Collaboration
&lt;br&gt;By Dan Kaminsky
&lt;br&gt;Wow. It's out. It's finally, finally out. Sweet!
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/477&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/477&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;------------------------------------
&lt;br&gt;1. Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31129
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-11
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31129&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31129&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft SQL Server 'sqlvdir.dll' ActiveX Control is prone to a buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
&lt;br&gt;&lt;br&gt;&amp;nbsp; This control is included with Microsoft SQL Server 2000; other versions may also be affected.
&lt;br&gt;&lt;br&gt;2. ZoneAlarm Security Suite AntiVirus Directory Path Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31124
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-11
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31124&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31124&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;ZoneAlarm Security Suite is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input when performing virus scans on long directory paths.
&lt;br&gt;&lt;br&gt;Remote attackers may leverage this issue to execute arbitrary code with SYSTEM-level privileges and allow the attacker to gain complete access to the vulnerable computer. Failed attacks will cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;This issue affects ZoneAlarm Security Suite 7.0.483.000; other versions may also be affected.
&lt;br&gt;&lt;br&gt;3. Maxthon Browser Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 31098
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31098&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31098&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Maxthon Browser is prone to a denial-of-service vulnerability.
&lt;br&gt;&lt;br&gt;An attacker may exploit this issue by enticing victims into opening a maliciously crafted webpage.
&lt;br&gt;&lt;br&gt;&amp;nbsp; Successfully exploiting this issue will allow the attacker to crash the application, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;This issue affects Maxthon Browser 2.1.4.443; other versions may also be affected.
&lt;br&gt;&lt;br&gt;4. Apple iTunes Misleading Firewall Warning Weakness
&lt;br&gt;BugTraq ID: 31090
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31090&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31090&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Apple iTunes is prone to a weakness caused by a misleading firewall warning that conveys erroneous information to users.
&lt;br&gt;&lt;br&gt;This issue may lead to a false sense of security, potentially aiding in network-based attacks.
&lt;br&gt;&lt;br&gt;Versions prior to Apple iTunes 8.0 are vulnerable to this issue.
&lt;br&gt;&lt;br&gt;5. Apple iTunes Third Party Driver Local Privilege Escalation Vulnerability
&lt;br&gt;BugTraq ID: 31089
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31089&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31089&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Apple iTunes is prone to a local privilege-escalation vulnerability due to an integer-overflow issue.
&lt;br&gt;&lt;br&gt;Local attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will result in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
&lt;br&gt;&lt;br&gt;This issue affects versions prior to iTunes 8.0 for Microsoft Windows XP and Microsoft Windows Vista.
&lt;br&gt;&lt;br&gt;6. Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities
&lt;br&gt;BugTraq ID: 31086
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31086&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31086&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Apple QuickTime is prone to multiple remote vulnerabilities that may allow remote attackers to execute arbitrary code and carry out denial-of-service attacks.
&lt;br&gt;&lt;br&gt;These issues arise when the application handles specially crafted PICT image files, movies, and QTVR movies. Successful exploits may allow attackers to gain remote unauthorized access in the context of a vulnerable user and to trigger a denial-of-service condition.
&lt;br&gt;&lt;br&gt;Versions prior to QuickTime 7.5.5 are affected.
&lt;br&gt;&lt;br&gt;7. Microsoft Windows Image Acquisition Logger ActiveX Control Arbitrary File Overwrite Vulnerability
&lt;br&gt;BugTraq ID: 31069
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-08
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31069&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31069&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows Image Acquisition Logger ActiveX control is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content. The issue occurs because the control fails to sanitize user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to overwrite files with attacker-supplied data, which will aid in further attacks.
&lt;br&gt;&lt;br&gt;8. Microsoft Office OneNote URL Handler Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31067
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31067&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31067&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Office OneNote is prone to a remote code-execution vulnerability.
&lt;br&gt;&lt;br&gt;An attacker could exploit this issue by enticing a victim to follow maliciously crafted URIs.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;9. Microsoft Windows Media Encoder 9 'wmex.dll' ActiveX Control Remote Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31065
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31065&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31065&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;The Microsoft Windows Media Encoder 9 ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;10. Microsoft Organization Chart Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31059
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-08
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31059&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31059&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Organization Chart is prone to a remote code-execution vulnerability because of a memory-access violation.
&lt;br&gt;&lt;br&gt;Remote attackers can exploit this issue by enticing victims into opening a maliciously crafted Organization Chart document.
&lt;br&gt;&lt;br&gt;Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
&lt;br&gt;&lt;br&gt;Microsoft Organization Chart 2.00,19 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;11. IBM DB2 Universal Database Server 8.2 Prior To Fixpak 17 Multiple Vulnerabilities
&lt;br&gt;BugTraq ID: 31058
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-01
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31058&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31058&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;IBM DB2 Universal Database Server is prone to multiple vulnerabilities:
&lt;br&gt;&lt;br&gt;- A remote denial-of-service issue related to CONNECT / ATTACH processing.
&lt;br&gt;- An unspecified vulnerability in the DB2FMP process.
&lt;br&gt;- A remote denial-of-service issue in DB2JDS.
&lt;br&gt;- The DB2FMP process executes with system privileges under Windows.
&lt;br&gt;&lt;br&gt;An attacker may exploit these issues to deny service to legitimate users. Other attacks may also be possible.
&lt;br&gt;&lt;br&gt;&amp;nbsp; The CONNECT / ATTACH issue may be related to the issue discussed in BID 27870 (IBM DB2 Universal Database Multiple Vulnerabilities).
&lt;br&gt;&lt;br&gt;Very few details are available regarding these issues. We will update this BID as more information emerges.
&lt;br&gt;&lt;br&gt;These issues affect &amp;nbsp;versions prior to IBM DB2 Universal Database Server 8.2 Fixpak 17.
&lt;br&gt;&lt;br&gt;12. Microsoft GDI+ BMP Integer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31022
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31022&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31022&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to an integer-overflow vulnerability.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue by enticing unsuspecting users to view a malicious BMP file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue allows remote attackers to corrupt memory and execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;13. Microsoft GDI+ WMF Image File Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31021
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31021&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31021&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a buffer-overflow vulnerability because the vector graphics linked library improperly allocates memory when parsing WMF image files.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow an attacker to corrupt memory and execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;14. Microsoft GDI+ GIF File Parsing Remote Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 31020
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31020&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31020&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a remote code-execution vulnerability because the vector graphics link library improperly parses GIF image files.
&lt;br&gt;&lt;br&gt;An attacker could exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts may crash applications that use the library.
&lt;br&gt;&lt;br&gt;15. Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability
&lt;br&gt;BugTraq ID: 31019
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31019&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31019&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a remote memory-corruption vulnerability that occurs when an application that uses the library tries to process a specially crafted EMF (Enhanced Metafile) image file.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;16. Microsoft GDI+ VML Heap-Based Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 31018
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31018&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31018&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft GDI+ is prone to a heap-based buffer-overflow vulnerability because the vector graphics link library improperly processes gradient sizes.
&lt;br&gt;&lt;br&gt;Successfully exploiting this issue would allow an attacker to corrupt heap memory and execute arbitrary code in the context of the currently logged-in user.
&lt;br&gt;&lt;br&gt;17. Microsoft September 2008 Advance Notification Multiple Vulnerabilities
&lt;br&gt;BugTraq ID: 31014
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-04
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31014&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31014&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft has released advance notification that the vendor will be releasing four security bulletins on September 9, 2008. The highest severity rating for these issues is 'Critical'.
&lt;br&gt;&lt;br&gt;Successfully exploiting these issues may allow remote or local attackers to compromise affected computers.
&lt;br&gt;&lt;br&gt;Individual records will be created to document the issues when the bulletins are released.
&lt;br&gt;&lt;br&gt;18. Wireshark 1.0.2 Multiple Vulnerabilities
&lt;br&gt;BugTraq ID: 31009
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31009&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Wireshark is prone to multiple vulnerabilities, including buffer-overflow and denial-of-service issues.
&lt;br&gt;&lt;br&gt;Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may be able to leverage some of these vulnerabilities to execute arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;These issues affect Wireshark 0.9.7 up to and including 1.0.2.
&lt;br&gt;&lt;br&gt;19. RETIRED: Moodle Multiple Remote File Include Vulnerabilities
&lt;br&gt;BugTraq ID: 30995
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30995&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30995&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Moodle is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
&lt;br&gt;&lt;br&gt;Exploiting these issues can allow an attacker to compromise the application and the underlying computer; other attacks are also possible.
&lt;br&gt;&lt;br&gt;These issues affect Moodle 1.8.4; other versions may also be affected.
&lt;br&gt;&lt;br&gt;NOTE: Further analysis indicates that these issues were previously documented in BID 28599 (kses Multiple Input Validation Vulnerabilities), so this BID is being retired.
&lt;br&gt;&lt;br&gt;20. Open-FTPD &amp;nbsp;Multiple Command Remote Denial of Service Vulnerabilities
&lt;br&gt;BugTraq ID: 30993
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30993&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30993&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Open-FTPD is prone to multiple remote denial-of-service vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;Attackers can exploit these issues to crash the affected application, denying service to legitimate users. Given the nature of these issues, attackers may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;Open-FTPD 1.2 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;21. @Mail and @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;BugTraq ID: 30992
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30992&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30992&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;@Mail and @Mail WebMail are prone to multiple cross-site scripting vulnerabilities because the applications fail to properly sanitize user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
&lt;br&gt;&lt;br&gt;These issues affect the following versions:
&lt;br&gt;&lt;br&gt;@Mail WebMail 5.05 running on Microsoft Windows
&lt;br&gt;@Mail 5.42 running on CentOS
&lt;br&gt;&lt;br&gt;Other versions running on different platforms may also be affected.
&lt;br&gt;&lt;br&gt;22. Softalk Mail Server 'APPEND' Command Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 30970
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-02
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30970&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30970&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Softalk Mail Server is prone to a remote denial-of-service vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue to crash the affected application, denying service to legitimate users.
&lt;br&gt;Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;Softalk Mail Server 8.5.1 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;23. Microsoft Windows Media Player SSPL File Sample Rate Remote Code-Execution Vulnerability
&lt;br&gt;BugTraq ID: 30550
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-09
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30550&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30550&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows Media Player is prone to a remote code-execution vulnerability.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;NOTE: Supported editions of Windows Server 2008 are not affected if installed using the Server Core installation option.
&lt;br&gt;&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;---------------------------------
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;-----------------------------
&lt;br&gt;To unsubscribe send an e-mail message to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19458252&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ms-secnews-unsubscribe@...&lt;/a&gt; from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit &lt;a href=&quot;http://www.securityfocus.com/newsletters&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/newsletters&lt;/a&gt;&amp;nbsp;and unsubscribe via the website.
&lt;br&gt;&lt;br&gt;If your email address has changed email &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19458252&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listadmin@...&lt;/a&gt; and ask to be manually removed.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;------------------------
&lt;br&gt;This issue is sponsored by Sponsored by Ironkey: The World's Most Secure Flash Drive
&lt;br&gt;&lt;br&gt;IronKey flash dives lock down your most sensitive data using today's most advanced security technology.
&lt;br&gt;IronKey uses military-grade AES CBC-mode hardware encryption that cannot be disabled by malware or an intruder and provides rugged and waterproof protection to safeguard your data.
&lt;br&gt;&lt;a href=&quot;https://www.iroky.com/forenterprise2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.iroky.com/forenterprise2&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SecurityFocus-Microsoft-Newsletter--411-tp19458252p19458252.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19319536</id>
	<title>SecurityFocus Microsoft Newsletter #410</title>
	<published>2008-09-04T13:38:48Z</published>
	<updated>2008-09-04T13:38:48Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
	<content type="html">SecurityFocus Microsoft Newsletter #410
&lt;br&gt;----------------------------------------
&lt;br&gt;&lt;br&gt;This issue is sponsored by Sponsored by Motorola Good technology
&lt;br&gt;&lt;br&gt;Mobile Device Security: Securing the Handheld, Securing the Enterprise. Mobile devices represent a tremendous productivity advantage for today's mobile worker. However, IT organizations must give consideration to the deployment of device security policies in order to provide the level of security that enterprises require 
&lt;br&gt;&lt;a href=&quot;http://dinclinx.com/Redirect.aspx?36;1267;45;189;0;13;1ea6f133b6f4a2b1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dinclinx.com/Redirect.aspx?36;1267;45;189;0;13;1ea6f133b6f4a2b1&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SECURITY BLOGS
&lt;br&gt;SecurityFocus has selected a few syndicated sources that stand out as conveying topics of interest for our community. We are proud to offer content from Matasano at this time and will be adding more in the coming weeks.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/blogs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/blogs&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------
&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.Get Off My Cloud
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.An Astonishing Collaboration
&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. Microsoft September 2008 Advance Notification Multiple Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Wireshark 1.0.2 Multiple Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. Moodle Multiple Remote File Include Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4. Open-FTPD &amp;nbsp;Multiple Command Remote Denial of Service Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5. @Mail and @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6. Softalk Mail Server 'APPEND' Command Remote Denial of Service Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7. Retired: Microsoft Windows GDI 'CreateDIBPatternBrushPt' Function Heap Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8. PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9. Ultra Office Control 'Save()' Method Arbitrary File Overwrite Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10. Ultra Office Control 'HttpUpload()' Method Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;11. LibTIFF 'tif_lzw.c' Remote Buffer Underflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12. JustSystems Ichitaro Document Handling Unspecified Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;13. Retired: DriveCrypt Incorrect BIOS API Usage Security Vulnerability
&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. SecurityFocus Microsoft Newsletter #409
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;---------------------
&lt;br&gt;1.Get Off My Cloud
&lt;br&gt;By Mark Rasch
&lt;br&gt;One of the features of Apple's device that appeals to me is the new MobileMe service, where you can &amp;quot;access and manage your email, contacts, calendar, photos, and files at me.com,&amp;quot; according to Apple. 
&lt;br&gt;More companies, among them Microsoft and Google, already allow people to store information and use common services online -- or &amp;quot;in the cloud&amp;quot; -- leading analysts to refer to the entire trend as &amp;quot;cloud computing.&amp;quot;
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/478&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/478&lt;/a&gt;&lt;br&gt;&lt;br&gt;2.An Astonishing Collaboration
&lt;br&gt;By Dan Kaminsky
&lt;br&gt;Wow. It's out. It's finally, finally out. Sweet!
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/477&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/477&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;------------------------------------
&lt;br&gt;1. Microsoft September 2008 Advance Notification Multiple Vulnerabilities
&lt;br&gt;BugTraq ID: 31014
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-04
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31014&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31014&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft has released advance notification that the vendor will be releasing four security bulletins on September 9, 2008. The highest severity rating for these issues is 'Critical'.
&lt;br&gt;&lt;br&gt;Successfully exploiting these issues may allow remote or local attackers to compromise affected computers.
&lt;br&gt;&lt;br&gt;Individual records will be created to document the issues when the bulletins are released.
&lt;br&gt;&lt;br&gt;2. Wireshark 1.0.2 Multiple Vulnerabilities
&lt;br&gt;BugTraq ID: 31009
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/31009&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/31009&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Wireshark is prone to multiple vulnerabilities, including buffer-overflow and denial-of-service issues.
&lt;br&gt;&lt;br&gt;Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may be able to leverage some of these vulnerabilities to execute arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;These issues affect Wireshark 0.9.7 up to and including 1.0.2.
&lt;br&gt;&lt;br&gt;3. Moodle Multiple Remote File Include Vulnerabilities
&lt;br&gt;BugTraq ID: 30995
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30995&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30995&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Moodle is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
&lt;br&gt;&lt;br&gt;Exploiting these issues can allow an attacker to compromise the application and the underlying computer; other attacks are also possible.
&lt;br&gt;&lt;br&gt;These issues affect Moodle 1.8.4; other versions may also be affected.
&lt;br&gt;&lt;br&gt;4. Open-FTPD &amp;nbsp;Multiple Command Remote Denial of Service Vulnerabilities
&lt;br&gt;BugTraq ID: 30993
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30993&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30993&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Open-FTPD is prone to multiple remote denial-of-service vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;Attackers can exploit these issues to crash the affected application, denying service to legitimate users. Given the nature of these issues, attackers may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;Open-FTPD 1.2 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;5. @Mail and @Mail WebMail Multiple Cross-Site Scripting Vulnerabilities
&lt;br&gt;BugTraq ID: 30992
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-03
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30992&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30992&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;@Mail and @Mail WebMail are prone to multiple cross-site scripting vulnerabilities because the applications fail to properly sanitize user-supplied input. 
&lt;br&gt;&lt;br&gt;An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
&lt;br&gt;&lt;br&gt;These issues affect the following versions:
&lt;br&gt;&lt;br&gt;@Mail WebMail 5.05 running on Microsoft Windows
&lt;br&gt;@Mail 5.42 running on CentOS
&lt;br&gt;&lt;br&gt;Other versions running on different platforms may also be affected.
&lt;br&gt;&lt;br&gt;6. Softalk Mail Server 'APPEND' Command Remote Denial of Service Vulnerability
&lt;br&gt;BugTraq ID: 30970
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-09-02
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30970&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30970&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Softalk Mail Server is prone to a remote denial-of-service vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;Attackers can exploit this issue to crash the affected application, denying service to legitimate users. 
&lt;br&gt;Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
&lt;br&gt;&lt;br&gt;Softalk Mail Server 8.5.1 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;7. Retired: Microsoft Windows GDI 'CreateDIBPatternBrushPt' Function Heap Overflow Vulnerability
&lt;br&gt;BugTraq ID: 30933
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-29
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30933&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30933&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Microsoft Windows is prone to a heap-based overflow vulnerability that resides in the GDI graphics library and can be triggered by a malformed EMF files.
&lt;br&gt;&lt;br&gt;A successful exploit of this vulnerability can allow a remote attacker to completely compromise the affected computer.
&lt;br&gt;&lt;br&gt;NOTE: This BID is being retired because further analysis indicates that this vulnerability is the same issue described in BID 28571 (Microsoft Windows GDI 'CreateDIBPatternBrushPt' Function Heap Overflow Vulnerability).
&lt;br&gt;&lt;br&gt;8. PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
&lt;br&gt;BugTraq ID: 30881
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-28
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30881&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30881&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;PureMessage for Microsoft Exchange is prone to multiple remote denial-of-service vulnerabilities because the application fails to properly process certain messages.
&lt;br&gt;&lt;br&gt;An attacker may exploit these issues to crash the affected application, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;PureMessage 3.0 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;9. Ultra Office Control 'Save()' Method Arbitrary File Overwrite Vulnerability
&lt;br&gt;BugTraq ID: 30863
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-27
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30863&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30863&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Ultra Office Control is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content. The issue occurs because the control fails to sanitize user-supplied input.
&lt;br&gt;&lt;br&gt;Successful exploits may allow attackers to compromise affected computers.
&lt;br&gt;&lt;br&gt;Ultra Office Control 2.0.2008.501 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;10. Ultra Office Control 'HttpUpload()' Method Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 30861
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-27
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30861&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30861&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Ultra Office Control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data. 
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;Ultra Office Control &amp;nbsp;2.0.2008.501 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;11. LibTIFF 'tif_lzw.c' Remote Buffer Underflow Vulnerability
&lt;br&gt;BugTraq ID: 30832
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30832&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30832&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;LibTIFF is prone to a remote buffer-underflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
&lt;br&gt;&lt;br&gt;&amp;nbsp;An attacker can exploit this issue to execute arbitrary malicious code in the context of the user running an application that uses the affected library. Failed exploit attempts will likely crash applications using the affected library.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;LibTIFF 3.7.2 and 3.8.2 are vulnerable.
&lt;br&gt;&lt;br&gt;12. JustSystems Ichitaro Document Handling Unspecified Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 30828
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30828&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30828&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Ichitaro is prone to an unspecified remote code-execution vulnerability.
&lt;br&gt;&lt;br&gt;Attackers may exploit this issue to execute arbitrary code within the context of the vulnerable application. Failed attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;Ichitaro 2008 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;13. Retired: DriveCrypt Incorrect BIOS API Usage Security Vulnerability
&lt;br&gt;BugTraq ID: 30818
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-08-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30818&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30818&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;DriveCrypt is prone to a security vulnerability that may cause a denial-of-service condition or allow attackers to gain access to plain text passwords.
&lt;br&gt;&lt;br&gt;Local attackers can exploit this issue to gain access to access to sensitive information or cause the affected computer to reboot.
&lt;br&gt;&lt;br&gt;DriveCrypt Plus Pack version 3.9 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;Note: This vulnerability is the same issue described in BID 15751 (Multiple Vendor BIOS Keyboard Buffer Password Persistence Weakness) therefore this BID is being retired.
&lt;br&gt;&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;---------------------------------
&lt;br&gt;1. SecurityFocus Microsoft Newsletter #409
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/88/495853&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/archive/88/495853&lt;/a&gt;&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;-----------------------------
&lt;br&gt;To unsubscribe send an e-mail message to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19319536&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ms-secnews-unsubscribe@...&lt;/a&gt; from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit &lt;a href=&quot;http://www.securityfocus.com/newsletters&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/newsletters&lt;/a&gt;&amp;nbsp;and unsubscribe via the website.
&lt;br&gt;&lt;br&gt;If your email address has changed email &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19319536&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listadmin@...&lt;/a&gt; and ask to be manually removed.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;------------------------
&lt;br&gt;This issue is sponsored by Sponsored by Motorola Good technology
&lt;br&gt;&lt;br&gt;Mobile Device Security: Securing the Handheld, Securing the Enterprise. Mobile devices represent a tremendous productivity advantage for today's mobile worker. However, IT organizations must give consideration to the deployment of device security policies in order to provide the level of security that enterprises require 
&lt;br&gt;&lt;a href=&quot;http://dinclinx.com/Redirect.aspx?36;1267;45;189;0;13;1ea6f133b6f4a2b1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dinclinx.com/Redirect.aspx?36;1267;45;189;0;13;1ea6f133b6f4a2b1&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SecurityFocus-Microsoft-Newsletter--410-tp19319536p19319536.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19228178</id>
	<title>SecurityFocus Microsoft Newsletter #409</title>
	<published>2008-08-29T14:54:19Z</published>
	<updated>2008-08-29T14:54:19Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
	<content type="html">&lt;br&gt;SecurityFocus Microsoft Newsletter #409
&lt;br&gt;----------------------------------------
&lt;br&gt;&lt;br&gt;This issue is sponsored by Sponsored by Motorola Good technology
&lt;br&gt;&lt;br&gt;Mobile Device Security: Securing the Handheld, Securing the Enterprise. Mobile devices represent a tremendous productivity advantage for today's mobile worker. However, IT organizations must give consideration to the deployment of device security policies in order to provide the level of security that enterprises require.
&lt;br&gt;&lt;a href=&quot;http://whitepapers.securityfocus.com/option,com_categoryreport/task,viewabstract/title,1267/id,/vid,36/cat,/pathway,no/srcid,189/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://whitepapers.securityfocus.com/option,com_categoryreport/task,viewabstract/title,1267/id,/vid,36/cat,/pathway,no/srcid,189/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;SECURITY BLOGS
&lt;br&gt;SecurityFocus has selected a few syndicated sources that stand out as conveying topics of interest for our community. We are proud to offer content from Matasano at this time and will be adding more in the coming weeks.
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/blogs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/blogs&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------
&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.Get Off My Cloud
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.An Astonishing Collaboration
&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Mono 'System.Web' HTTP Header Injection Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3. Ultra Office Control 'Save()' Method Arbitrary File Overwrite Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4. Ultra Office Control 'HttpUpload()' Method Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5. LibTIFF 'tif_lzw.c' Remote Integer Underflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6. JustSystems Ichitaro Document Handling Unspecified Code Execution Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7. Retired: DriveCrypt Incorrect BIOS API Usage Security Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8. Microsoft Windows Media Services 'nskey.dll' ActiveX Control Remote Buffer Overflow Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;9. Folder Lock Weak Password Encryption Local Information Disclosure Vulnerability
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10. Opera Web Browser 9.51 Multiple Security Vulnerabilities
&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. SecurityFocus Microsoft Newsletter #408
&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; FRONT AND CENTER
&lt;br&gt;---------------------
&lt;br&gt;1.Get Off My Cloud
&lt;br&gt;By Mark Rasch
&lt;br&gt;One of the features of Apple's device that appeals to me is the new MobileMe service, where you can &amp;quot;access and manage your email, contacts, calendar, photos, and files at me.com,&amp;quot; according to Apple. 
&lt;br&gt;More companies, among them Microsoft and Google, already allow people to store information and use common services online -- or &amp;quot;in the cloud&amp;quot; -- leading analysts to refer to the entire trend as &amp;quot;cloud computing.&amp;quot;
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/478&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/478&lt;/a&gt;&lt;br&gt;&lt;br&gt;2.An Astonishing Collaboration
&lt;br&gt;By Dan Kaminsky
&lt;br&gt;Wow. It's out. It's finally, finally out. Sweet!
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/columnists/477&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/columnists/477&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;II. &amp;nbsp;MICROSOFT VULNERABILITY SUMMARY
&lt;br&gt;------------------------------------
&lt;br&gt;1. PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
&lt;br&gt;BugTraq ID: 30881
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-28
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30881&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30881&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;PureMessage for Microsoft Exchange is prone to multiple remote denial-of-service vulnerabilities because the application fails to properly process certain messages.
&lt;br&gt;&lt;br&gt;An attacker may exploit these issues to crash the affected application, denying service to legitimate users.
&lt;br&gt;&lt;br&gt;PureMessage 3.0 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;2. Mono 'System.Web' HTTP Header Injection Vulnerability
&lt;br&gt;BugTraq ID: 30867
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-08-20
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30867&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30867&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Mono is prone to a vulnerability that allows attackers to inject arbitrary HTTP headers because it fails to sanitize input.
&lt;br&gt;&lt;br&gt;By inserting arbitrary headers into an HTTP response, attackers may be able to launch cross-site request-forgery, cross-site scripting, HTTP-request-smuggling, and other attacks.
&lt;br&gt;&lt;br&gt;This issue affects Mono 2.0 and earlier.
&lt;br&gt;&lt;br&gt;3. Ultra Office Control 'Save()' Method Arbitrary File Overwrite Vulnerability
&lt;br&gt;BugTraq ID: 30863
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-27
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30863&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30863&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Ultra Office Control is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content. The issue occurs because the control fails to sanitize user-supplied input.
&lt;br&gt;&lt;br&gt;Successful exploits may allow attackers to compromise affected computers.
&lt;br&gt;&lt;br&gt;Ultra Office Control 2.0.2008.501 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;4. Ultra Office Control 'HttpUpload()' Method Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 30861
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-27
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30861&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30861&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Ultra Office Control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data. 
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;Ultra Office Control &amp;nbsp;2.0.2008.501 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;5. LibTIFF 'tif_lzw.c' Remote Integer Underflow Vulnerability
&lt;br&gt;BugTraq ID: 30832
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30832&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30832&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;LibTIFF is prone to an integer-underflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
&lt;br&gt;&lt;br&gt;&amp;nbsp;An attacker can exploit this issue to execute arbitrary malicious code in the context of the user running an application that uses the affected library. Failed exploit attempts will likely crash applications using the affected library.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;LibTIFF 3.7.2 and 3.8.2 are vulnerable.
&lt;br&gt;&lt;br&gt;6. JustSystems Ichitaro Document Handling Unspecified Code Execution Vulnerability
&lt;br&gt;BugTraq ID: 30828
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-26
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30828&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30828&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Ichitaro is prone to an unspecified remote code-execution vulnerability.
&lt;br&gt;&lt;br&gt;Attackers may exploit this issue to execute arbitrary code within the context of the vulnerable application. Failed attempts will result in a denial-of-service condition.
&lt;br&gt;&lt;br&gt;Ichitaro 2008 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;7. Retired: DriveCrypt Incorrect BIOS API Usage Security Vulnerability
&lt;br&gt;BugTraq ID: 30818
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-08-25
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30818&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30818&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;DriveCrypt is prone to a security vulnerability that may cause a denial-of-service condition or allow attackers to gain access to plain text passwords.
&lt;br&gt;&lt;br&gt;Local attackers can exploit this issue to gain access to access to sensitive information or cause the affected computer to reboot.
&lt;br&gt;&lt;br&gt;DriveCrypt Plus Pack version 3.9 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;Note: This vulnerability is the same issue described in BID 15751 (Multiple Vendor BIOS Keyboard Buffer Password Persistence Weakness) therefore this BID is being retired.
&lt;br&gt;&lt;br&gt;8. Microsoft Windows Media Services 'nskey.dll' ActiveX Control Remote Buffer Overflow Vulnerability
&lt;br&gt;BugTraq ID: 30814
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-22
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30814&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30814&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;The Microsoft Windows Media Services ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
&lt;br&gt;&lt;br&gt;An attacker can exploit this issue to execute arbitrary code in the context of an application using the affected ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
&lt;br&gt;&lt;br&gt;'nskey.dll' 4.1.00.3917 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;9. Folder Lock Weak Password Encryption Local Information Disclosure Vulnerability
&lt;br&gt;BugTraq ID: 30771
&lt;br&gt;Remote: No
&lt;br&gt;Date Published: 2008-08-20
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30771&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30771&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Folder Lock is prone to an information-disclosure vulnerability because it stores credentials in an insecure manner.
&lt;br&gt;&lt;br&gt;A local attacker can exploit this issue to obtain passwords used by the application, which may aid in further attacks.
&lt;br&gt;&lt;br&gt;Folder Lock 5.9.5 is vulnerable; other versions may also be affected.
&lt;br&gt;&lt;br&gt;10. Opera Web Browser 9.51 Multiple Security Vulnerabilities
&lt;br&gt;BugTraq ID: 30768
&lt;br&gt;Remote: Yes
&lt;br&gt;Date Published: 2008-08-20
&lt;br&gt;Relevant URL: &lt;a href=&quot;http://www.securityfocus.com/bid/30768&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/bid/30768&lt;/a&gt;&lt;br&gt;Summary:
&lt;br&gt;Opera Web Browser is prone to multiple security vulnerabilities.
&lt;br&gt;&lt;br&gt;Successful exploits may allow attackers to:
&lt;br&gt;- cause denial-of-service conditions
&lt;br&gt;- violate the same-origin policy
&lt;br&gt;- carry out phishing and cross-domain attacks
&lt;br&gt;- execute arbitrary script code in the browser of an unsuspecting user in the context of an affected site
&lt;br&gt;- steal cookie-based authentication credentials
&lt;br&gt;- present insecure websites as secure
&lt;br&gt;- obtain sensitive information
&lt;br&gt;- mislead a user
&lt;br&gt;- carry out other attacks
&lt;br&gt;&lt;br&gt;Versions prior to Opera 9.52 are vulnerable.
&lt;br&gt;&lt;br&gt;III. MICROSOFT FOCUS LIST SUMMARY
&lt;br&gt;---------------------------------
&lt;br&gt;1. SecurityFocus Microsoft Newsletter #408
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/88/495736&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/archive/88/495736&lt;/a&gt;&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;UNSUBSCRIBE INSTRUCTIONS
&lt;br&gt;-----------------------------
&lt;br&gt;To unsubscribe send an e-mail message to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19228178&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ms-secnews-unsubscribe@...&lt;/a&gt; from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit &lt;a href=&quot;http://www.securityfocus.com/newsletters&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/newsletters&lt;/a&gt;&amp;nbsp;and unsubscribe via the website.
&lt;br&gt;&lt;br&gt;If your email address has changed email &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19228178&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listadmin@...&lt;/a&gt; and ask to be manually removed.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; SPONSOR INFORMATION
&lt;br&gt;------------------------
&lt;br&gt;This issue is sponsored by Sponsored by Motorola Good technology
&lt;br&gt;&lt;br&gt;Mobile Device Security: Securing the Handheld, Securing the Enterprise. Mobile devices represent a tremendous productivity advantage for today's mobile worker. However, IT organizations must give consideration to the deployment of device security policies in order to provide the level of security that enterprises require.
&lt;br&gt;&lt;a href=&quot;http://whitepapers.securityfocus.com/option,com_categoryreport/task,viewabstract/title,1267/id,/vid,36/cat,/pathway,no/srcid,189/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://whitepapers.securityfocus.com/option,com_categoryreport/task,viewabstract/title,1267/id,/vid,36/cat,/pathway,no/srcid,189/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SecurityFocus-Microsoft-Newsletter--409-tp19228178p19228178.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19153693</id>
	<title>SecurityFocus Microsoft Newsletter #408</title>
	<published>2008-08-25T14:52:06Z</published>
	<updated>2008-08-25T14:52:06Z</updated>
	<author>
		<name>Rob Keith</name>
	</author>
