two
Volume 5, Number 6 -- February 13, 2008

Monster Patch Tuesday Yields 11 Fixes for 17 Flaws

Published: February 13, 2008

by Alex Woodie

Windows administrators' love lives may have to be put on hold this week as a monstrous Patch Tuesday wave of security fixes threatens to consume their Valentine's Day. Microsoft released 11 patches addressing 17 security vulnerabilities yesterday, including seven critical patches for a range of remote code execution problems. A handful of Office flaws, new problems in IE, and two new denial of service attacks combine to make February's Patch Tuesday the biggest one in a year.

If the idea of cuddling up all night with a server or workstation appeals to you, you're going to be in hog heaven this week, according to Paul Zimski, senior director of market strategy at Lumension Security.

"This month's patches are going to require a great deal of man hours for IT admins, from determining what is affected to the testing and deployment processes," he says. "IT administrators might be spending this Valentine's Day in the office."

Zimski says the size and scope of the fixes threaten to overwhelm Windows shops. "Because so many critical patches affect so many applications," he says, "these are widespread enough to have a bigger effect than we've seen in a year and they are going to require the utmost attention and energy." If there's one positive aspect to yesterday's tidal wave of patches, it's that there's only one so-called "zero-day" flaw that's already being exploited, and it's not a critical flaw.

Let's start the fun with the critical patches first. MS08-007 addresses a critical vulnerability in the WebDAV protocol that could allow an attacker to gain full control over a computer running any recent version of Windows. The specific flaw, called the WebDAV Mini-Redirector vulnerability, was found by the COSEINC Vulnerability Research Lab of Singapore.

Another remote code execution vulnerability is fixed with MS08-008. This patch addresses the OLE Heap Overrun flaw, which is present in all recent versions of Windows except Widows Vista SP1 and Windows Server 2008. Microsoft says this flaw was discovered by Ryan Smith and Alex Wheeler of IBM's ISS X-Force subsidiary.

MS08-009 fixes a critical flaw in several versions of MS-Word that could give an attacker complete control of an affected system. This flaw, which could be exploited over e-mail and the Web, affects Word 2000, Word XP, Word 2003, and Word Viewer 2003, but doesn't affect more recent versions of the program. It was discovered by Rubén Santamarta, a European security researcher with reversemode.com, Microsoft says.

Four critical remote code execution flaws in Internet Explorer are fixed with MS08-010, which is being distributed as a cumulative security update for the Web browser. The flaws--which include the HTML Rendering Memory Corruption Vulnerability, the Property Memory Corruption Vulnerability, the Argument Handling Memory Corruption Vulnerability, and the ActiveX Object Memory Corruption Vulnerability--affect IE versions 5, 6, and 7 running across all recent versions of Windows, although Windows Server 2003's default settings will protect users from two of the vulnerabilities. The ActiveX flaw is being actively exploited, but none of the others are, according to Microsoft. Security researchers with several organizations, including Security Objectives, Tipping Point, the Zero Day Initiative, VeriSign iDefense VCP, and ADLABS were credited with bringing the problems to Microsoft's attention.

Two remote code execution vulnerabilities in Office Publisher are fixed with MS08-012. Specially crafted Publisher files could allow an attacker to gain full control over an affected system running the 2000, XP, and 2003 versions of Publisher. Microsoft says neither flaw is being exploited, and credits Fortinet Security Research with reporting the flaws.

Yet more critical security flaws in Office were revealed with MS08-0013, which fixes the Office Execution Jump remote code execution vulnerability in Office 2000, Office XP, Office 2003, and Office 2004 for Mac. This flaw could enable an attacker to gain complete control of an affected system when a malformed Office file is opened. It's not being executed, according to Microsoft, which credits Shaun Colley of NGSSoftware with reporting the problem.

Important Fixes

Microsoft lumped two denial of service (DOS) attacks into the important category this month. One of these patches, MS08-003 fixes a problem in the LDAP implementation in Active Directory running on Microsoft Windows 2000 Server, Windows Server 2003, and Windows XP. The flaw is most dangerous on Windows 2000 Server, where it garnered an "important" rating. The flaw, which was reported by Thomas Garnier of the U.S.-French security researcher SkyRecon Systems, was only given a "moderate" rating on the other operating systems.

Tyler Reguly, a security researcher with nCircle, called MS08-003 "this month's monster patch." Although it is "only" a DOS vulnerability, "the impact on availability of server and client resources could be extremely widespread in enterprise networks," Reguly warned.

Another DOS flaw was fixed with MS08-004. A problem in the TCP/IP services in Windows Vista could allow an attacker to launch a DOS attack against a victim over the Internet. Microsoft says this flaw was reported by Whitestein Technologies.

Reguly rates MS08-004 as critical because it could lead to a rogue DHCP server leaving a large number of Vista workstations unavailable. "With the large scale Vista conversions underway, this is of particular concern for large enterprises," he states.

The fun continues with MS08-005, which fixes an "important" elevation of privilege problem in the Internet Information Services (IIS) Web server that could compromise all versions of Windows (except the latest Vista SP1 and Windows Server 2008 releases). Microsoft says the flaw, known as the File Change Notification vulnerability, is not being exploited.

Another problem with IIS was reported with MS08-006, which fixes a remote code execution vulnerability that afflicts all versions of Windows XP and Windows Server 2003. This flaw, which has to do with how IIS serves ASP Web pages, is not being exploited, the company says.

Three security flaws in Microsoft Works file converter were fixed with MS08-011. Problems with validating section length headers, index tables, and field lengths could take over an affected computer. The problems, which only exist in Office 2003, Works 8.0, and Works Suite 2005, are not being exploited, and were discovered by VeriSign's iDefense team and IBM's ISS X-Force team.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
GABRIEL CONSULTING GROUP

Have a bunch of x86 servers?

Take the GCG x86 Server Vendor Preference Survey
and get a $10 Amazon certificate.

Your privacy is protected.
No spam. No sales pitches. No surprises.
All we want is an honest opinion.

Follow this link to take part in this survey.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
Vision Solutions:  Disaster Recovery and Compliance – Get the Free e-Book!
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
WDSC Is Out, Rational Developer for System i Is In

Q&A with MKS CEO Philip Deck: Automating the Automaters

The System i Loses One Big Account and a Mid-Sized One, Too

As I See It: Why IT Will Save the Economy

High Voltage DC Systems for Data Centers Cut Power Use

The Linux Beacon
Alfresco Puts Out Second Annual Open Source Barometer Report

Rock and Tukwila Were the Stars of ISSCC Last Week

Virtualization Software Player Announcement Roundup

As I See It: Why IT Will Save the Economy

Who Needs a Web Application Firewall?

Four Hundred Stuff
Bellamy Boosts Sales, Thanks to looksoftware GUI

The Genie's Browser Presence Grows

QSystem Monitor Gains Disk Cleanup Functions

Single Person RPG Shop Produces Sharp Self-Service Portal

Centerfield Debuts Installation Service for DB2 Web Query

Big Iron
A Mainframe Renaissance

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Setting Up A PHP/Web Environment On System i: Where Do I Start?

Don't Let SQL Name Your Baby

A Checklist For Moving System i Boxes

System i PTF Guide
February 9, 2008: Volume 10, Number 6

February 2, 2008: Volume 10, Number 5

January 26, 2008: Volume 10, Number 4

January 19, 2008: Volume 10, Number 3

January 12, 2008: Volume 10, Number 2

January 5, 2008: Volume 10, Number 1

The Unix Guardian
The Power6 Server Ramp: Better Than Expected

Rock and Tukwila Are the Stars of ISSCC This Week

Who Needs a Web Application Firewall?

The X Factor: Survive, Adapt, Repeat

High Voltage DC Systems for Data Centers Cut Power Use

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Gabriel Consulting Group
IT Security
Storage Guardian
World Data Products
Vibrant Technologies


Printer Friendly Version


TABLE OF CONTENTS
Monster Patch Tuesday Yields 11 Fixes for 17 Flaws

Yahoo Rejects Microsoft's Bid; Google's Ad Revenues Hiccup

HP Puts Out a Four-Socket Itanium Blade Server

System Center Service Manager Delayed Two Years by Microsoft

Citrix Puts the Xen Brand Everywhere, Previews XenServer 4.1

But Wait, There's More:

Shavlik Updates Windows Patch Management with NetChk Protect 6.0 . . . Consumer Technologies Help Smaller Business, Yankee Finds . . . Gartner Looks at the Big IT Issues for the Next Few Years . . . Dell Rejiggers Distribution for Athlon and Opteron Machines . . . Microsoft Co-Founds OpenID . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement