There has been found a vulnerability in Microsoft Internet Explorer (IE) 7 web browser. The vulnerability is related to IE 7 way to handle XML content. By exploiting the vulnerability an attacker may be able to execute arbitrary code with currently logged on user's rights or cause a denial of service in vulnerable system.
The vulnerability can be exploited by luring user to open specifically crafted web site. Exploits are publicly available and the issue is being actively exploited in the wild.
Affected are Internet Explorer 7 on Microsoft Windows XP, Windows Server 2003, Windows Server 2008 and Windows Vista; other versions may also be affected.
Currently there's no patch available to fix the issue. Reportedly, Microsoft is investigating the issue and will release updates upon completion of this investigation. Please see the Microsoft advisory for more information.
More information:
- http://www.vupen.com/english/advisories/2008/3391
- http://www.securityfocus.com/bid/32721/info
- http://isc.sans.org/diary.html?storyid=5458
- http://research.eeye.com/html/alerts/zeroday/20081209.html
- http://www.avertlabs.com/research/blog/index.php/2008/12/09/yet-another-unpatched-drive-by-exploit-found-on-the-web/
- http://secunia.com/advisories/33089/
Thursday, December 11, 2008
Vulnerability In Microsoft WordPad
Microsoft has released an advisory on a vulnerability in WordPad. Vulnerability is in WordPad text converter and could allow remote code execution. It can be exploited by luring user to open specifically crafted Word 97 file with WordPad. Microsoft says that it's investigating the issue.
Mentioned vulnerability affects Microsoft WordPad on Windows 2000 SP 4, Windows XP SP 2, Windows Server 2003 SP 1 and Windows Server 2003 SP 2. At the moment, general fix doesn't exist. Windows XP users can fix the vulnerability by installing service pack 3.
To limit vulnerability effects opening .doc, .wri or .rtf files with unknown origin should be avoided.
According to the advisory effects can be limited also by disabling the WordPad Text Converter for Word 97 file format. That will be done by running following command:
echo y| cacls "%ProgramFiles%\Windows NT\Accessories\mswrd8.wpc" /E /P everyone:N
About the impact of the workaround can be read from the advisory.
Mentioned vulnerability affects Microsoft WordPad on Windows 2000 SP 4, Windows XP SP 2, Windows Server 2003 SP 1 and Windows Server 2003 SP 2. At the moment, general fix doesn't exist. Windows XP users can fix the vulnerability by installing service pack 3.
To limit vulnerability effects opening .doc, .wri or .rtf files with unknown origin should be avoided.
According to the advisory effects can be limited also by disabling the WordPad Text Converter for Word 97 file format. That will be done by running following command:
echo y| cacls "%ProgramFiles%\Windows NT\Accessories\mswrd8.wpc" /E /P everyone:N
About the impact of the workaround can be read from the advisory.
Tuesday, December 9, 2008
Security Update For December 2008 From Microsoft
Microsoft released its monthly security update packet today. December update contains eight updates. Six of those are critical and two important. In total, the updates fix 28 vulnerabilities.
Summary of affected software:
- Windows and its components,
- Microsoft Office,
- Microsoft developer tools and software,
- Sharepoint Server.
Among the updates a new version of Microsoft Windows Malicious Software Removal Tool is released too.
More information about the updates can be read here.
The easist way to get the updates is to use Microsoft automatic update service.
Summary of affected software:
- Windows and its components,
- Microsoft Office,
- Microsoft developer tools and software,
- Sharepoint Server.
Among the updates a new version of Microsoft Windows Malicious Software Removal Tool is released too.
More information about the updates can be read here.
The easist way to get the updates is to use Microsoft automatic update service.
PHP Version 5.2.8 Released
There has been released version 5.2.8 of PHP scripting language. New version fixes security problem that arose in version 5.2.7. The problem was in magic_quotes_gpc functionality and was caused by an incorrect fix to the filter extension.
All users who have upgraded to 5.2.7 are encouraged to upgrade to this release, alternatively they can apply a work-around for the bug by changing "filter.default_flags=0" in php.ini.
Source
All users who have upgraded to 5.2.7 are encouraged to upgrade to this release, alternatively they can apply a work-around for the bug by changing "filter.default_flags=0" in php.ini.
Source
Sunday, December 7, 2008
Koobface Spreading On Facebook
Social networking service Facebook told to Computerworld that they're quickly updating their security systems to minimize further impact of malware spreading on Facebook. Passwords of infected accounts are being resetted and spam messages are being removed. Facebook is also coordinating with third parties to remove redirects to malicious content elsewhere on the web.
The guilty one in the problem is a new variant of Koobface worm which is targeting Facebook. Last summer its earlier variants caused harm to Facebook and MySpace users.
In a nutshell, bad guys try to fool Facebook victims by sending spam with a link claiming to contain a video. When user clicks the link (s)he is redirected to a page that then displays a fake error message claiming that Adobe System Inc.'s Flash is out of date, and prompts user to download an update. Instead of being an update the executable file installs variant of Koobface worm which in turn installs a background proxy server that redirects all Web traffic.
On infected system at least all searches made on Google, Microsoft and Yahoo search engines are redirected to find-www.net web address. The hackers are making money by redirecting users' searches to their own results, collecting cash from the ensuing clicks.
Facebook has posted a short message on its security page acknowledging the worm's attack. The notice urged users whose accounts had already been compromised to scan their PCs for malware and then reset their passwords.
The guilty one in the problem is a new variant of Koobface worm which is targeting Facebook. Last summer its earlier variants caused harm to Facebook and MySpace users.
In a nutshell, bad guys try to fool Facebook victims by sending spam with a link claiming to contain a video. When user clicks the link (s)he is redirected to a page that then displays a fake error message claiming that Adobe System Inc.'s Flash is out of date, and prompts user to download an update. Instead of being an update the executable file installs variant of Koobface worm which in turn installs a background proxy server that redirects all Web traffic.
On infected system at least all searches made on Google, Microsoft and Yahoo search engines are redirected to find-www.net web address. The hackers are making money by redirecting users' searches to their own results, collecting cash from the ensuing clicks.
Facebook has posted a short message on its security page acknowledging the worm's attack. The notice urged users whose accounts had already been compromised to scan their PCs for malware and then reset their passwords.
Friday, December 5, 2008
PHP Version 5.2.7 Is Out
PHP development team has released 5.2.7 version of PHP scripting language. New version focuses on improving the stability of the PHP 5.2.x branch with over 120 bug fixes. Several of these are security related. All PHP users are recommended to upgrade their versions to this latest release.
More details about 5.2.7 release can be read from official version 5.2.7 release announcement.
More details about 5.2.7 release can be read from official version 5.2.7 release announcement.
Wednesday, December 3, 2008
Java SE Runtime Environment (JRE) Update Available
Sun has released update for Java SE Runtime Environment (JRE) 6. JRE allows end-users to run Java applications. The latest update can be downloaded from Sun's <Java SE Downloads site.
Unlike Update 10, Update 11 is a bug fix and security release. Upgrading to it is advisable. More information about contents of the update can be read from Release Notes of Java SE 6 Update 11.
Unlike Update 10, Update 11 is a bug fix and security release. Upgrading to it is advisable. More information about contents of the update can be read from Release Notes of Java SE 6 Update 11.
Subscribe to:
Posts (Atom)