Microsoft released yesterday (7/8/2008) four update packets that fix nine vulnerabilities. Along with the vulnerability fixes a new version of Microsoft Windows Malicious Software Removal Tool was released too.
MS08-037 update fixes two vulnerabilities in Windows Domain Name System (DNS). Affected systems are all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003 and Windows Server 2008.
MS08-038 update fixes a vulnerability in Windows Explorer that could allow remote code execution when a specially crafted saved-search file is opened and saved. Affected are all supported editions of Windows Vista and Windows Server 2008.
MS08-039 update fixes two vulnerabilities in Outlook Web Access (OWA) for Microsoft Exchange Server. This update is rated important for all supported editions of Microsoft Exchange Server 2003 and Microsoft Exchange Server 2007.
MS08-040 update fixes four vulnerabilities in SQL Server memory handling. Update is rated important for supported releases of SQL Server 7.0, SQL Server 2000, SQL Server 2005, Microsoft Data Engine (MSDE) 1.0, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (WMSDE), and Windows Internal Database (WYukon).
More information about the updates can be read from Microsoft Security Bulletins (links above).
The easiest way to update is to use Microsoft automatic update service.
Wednesday, July 9, 2008
Tuesday, July 8, 2008
Vulnerability In Microsoft Office Snapshot Viewer ActiveX control
There has been found a vulnerability in Microsoft Office Snapshot Viewer ActiveX control (snapview.ocx). The vulnerability can allow a remote, unauthenticated attacker to download arbitrary files to arbitrary locations. Vulnerability can be used for example to place files in Windows startup folder to make them executed when system starts up on next reboot. US-CERT tell that they have received reports of active exploitation of the vulnerability.
Vulnerable are Office versions 2000, XP and 2003 which all contain meantioned ActiveX control. The ActiveX control is also shipped with the standalone Snapshot Viewer.
At the moment there isn't a fix available for the vulnerability. As a workaround it's recommended to disable the vulnerable ActiveX control by following instructions in Microsoft Security Advisory.
More information on the vulnerability:
US-CERT vulnerability note
Microsoft Security Response Center (MSRC) blog
Vulnerable are Office versions 2000, XP and 2003 which all contain meantioned ActiveX control. The ActiveX control is also shipped with the standalone Snapshot Viewer.
At the moment there isn't a fix available for the vulnerability. As a workaround it's recommended to disable the vulnerable ActiveX control by following instructions in Microsoft Security Advisory.
More information on the vulnerability:
US-CERT vulnerability note
Microsoft Security Response Center (MSRC) blog
Sunday, July 6, 2008
Opera 9.51 Released
There's been released version 9.51 of Opera web browser. New version contains a fix for Windows version vulnerability that could be used to execute arbitrary code. Opera Software will publish more information on the vulnerability at a later date. Also the issue where canvas -functions could reveal data from random places in memory is fixed. Other details about the update can be read here.
Opera users can download updated version here.
Opera users can download updated version here.
Friday, July 4, 2008
Mozilla Fixes Vulnerabilities In Firefox Web Browsers
Mozilla has released update that fixes 13 vulnerabilities in Firefox web browser.
Vulnerable versions are:
Mozilla Firefox versions before 2.0.0.15
Mozilla SeaMonkey versions before 1.1.10
Mozilla Thunderbird 2.0.0.14 and versions before it.
Mozilla Firefox 2.0.0.x version users are advised to update their versions to 2.0.0.15 (or version 3) and Mozilla SeaMonkey users should get version 1.1.10. There isn't a update for Mozilla Thunderbird yet and that's why its users are advised to turn JavaScript support off until the fix is released.
Firefox 3 is not vulnerable to these reported vulnerabilities. However, vulnerability that was reported shortly after Firefox 3 release is still waiting to be fixed.
Vulnerable versions are:
Mozilla Firefox versions before 2.0.0.15
Mozilla SeaMonkey versions before 1.1.10
Mozilla Thunderbird 2.0.0.14 and versions before it.
Mozilla Firefox 2.0.0.x version users are advised to update their versions to 2.0.0.15 (or version 3) and Mozilla SeaMonkey users should get version 1.1.10. There isn't a update for Mozilla Thunderbird yet and that's why its users are advised to turn JavaScript support off until the fix is released.
Firefox 3 is not vulnerable to these reported vulnerabilities. However, vulnerability that was reported shortly after Firefox 3 release is still waiting to be fixed.
Thursday, July 3, 2008
Vulnerability in VLC Media Player
There has been found a vulnerability in VLC Media Player. Vulnerability is related to integer overflow that may occur when specifically crafted WAV file is opened. Successful exploitation may allow execution of arbitrary code.
Vulnerability is confirmed in version 0.8.6h but also previous versions may be affected.
Vulnerability is fixed in an upcoming version 0.8.6i. Meanwhile, it's recommended to not open unknown WAV files.
Vulnerability is confirmed in version 0.8.6h but also previous versions may be affected.
Vulnerability is fixed in an upcoming version 0.8.6i. Meanwhile, it's recommended to not open unknown WAV files.
Wednesday, July 2, 2008
Microsoft MVP Award
Tuesday, July 1, 2008
F-Secure Rescue CD 3.00 Released
F-Secure released over a week ago Rescue CD version 3.00 that can be used to scan the system for malware. Program renames all files containing malware to .virus file extension. Following list is quoted from Release Notes of Rescue CD:
According to F-Secure the big changes compared to 2.00 include a proper manual for the product, ability to update databases manually with a USB stick, better hardware support (Knoppix version 5.3.1), upgraded NTFS driver (NTFS-3G 1.2506) and the ability to detect MBR viruses.
Rescue CD can't be used to scan encrypted files or folders.
Rescue CD will by default scan:
* all hard drives in the computer
* all USB drives attached to the computer
* Windows FAT and NTFS filesystems
* Virus definition databases are updated automatically if the computer has
an internet connection
* Virus definition databases can be updated manually by using a USB drive
* The Rescue CD Guide (pdf) has step by step instructions how use the CD
To use F-Secure Rescue CD on a computer the computer must:
* Be x86 compatible
* Have at least 256MB of RAM
* Be able to boot from a CD
* Be able to connect to the Internet or be able to use a USB drive
According to F-Secure the big changes compared to 2.00 include a proper manual for the product, ability to update databases manually with a USB stick, better hardware support (Knoppix version 5.3.1), upgraded NTFS driver (NTFS-3G 1.2506) and the ability to detect MBR viruses.
Rescue CD can't be used to scan encrypted files or folders.
Subscribe to:
Posts (Atom)