two
Volume 6, Number 23 -- June 11, 2008

Fixes for Critical Security Flaws Issued by Microsoft

Published: June 11, 2008

by Alex Woodie

It's the second Tuesday of the month, which means that the cycle of life begins anew in the Microsoft TechNet Security division, which yesterday issued seven patches addressing 10 vulnerabilities in the Windows operating system and associated programs. Standouts from June's patch pack include a critical vulnerability in Windows' Bluetooth stack that could potentially enable drive-by hacking over wireless networks, another cumulative IE release, and an Active Directory flaw that will affect nearly every corporation.

3 Patches for 5 Critical Flaws

A critical vulnerability with Windows' Bluetooth stack is addressed with Security Bulletin MS08-030. According to Microsoft, the flaw could allow attackers to gain complete control over Windows XP and Vista machines by flooding the computers with bogus service requests. The flaw has not been publicly announced (Microsoft did not say who reported it), and is not being exploited in the wild, the company says.

Two critical vulnerabilities in the Internet Explorer Web browser are addressed with Security Bulletin MS08-031, which is being delivered as a cumulative update. The patch fixes the HTML Objects Memory Corruption vulnerability, which could allow an attacker to take complete control of an affected system by tricking a user into viewing a malformed Web page, as well as the Request Header Cross-Domain Information Disclosure vulnerability, which could allow an attacker to view a victim's private information if they view a malformed Web page. Neither vulnerability is currently being exploited, according to Microsoft, which credits researchers working with TippingPoint and the Zero Day Initiative for reporting the HTML Objects Memory Corruption Vulnerability.

The final critical patch, Security Bulletin MS08-033, fixes two problems with Microsoft's DirectX versions 7 through 10 affecting nearly all versions of Windows and Windows Server over the last eight years. The MJPEG Decoder vulnerability and the SAMI Format Parsing vulnerability could give attackers total control over victims' machines by tricking them into opening malformed files. IBM Internet Security Systems X-Force team and Tipping Point and the Zero Day Initiative get credit for reporting the vulnerabilities, which aren't in general circulation, according to Microsoft.

3 Patches for 4 Important Flaws

An elevation of privilege flaw affecting Windows 2000 Server and Windows Server 2003 has been addressed with Security Bulletin MS08-034. A problem with the way that the Windows Internet Name Service (WINS) validates data structures within WINS packets could potentially allow an attacker to take complete control over an affected system. Luckily, it's not being exploited in the wild yet, according to Microsoft.

Security Bulletin MS08-035 addresses a potentially troublesome denial of service (DOS) problem in Active Directory that could affect businesses relying on Active Directory. The flaw could enable an attacker to bring down a server or a PC by flooding it with malformed LDAP requests. Nearly all recent versions of Windows are affected by the Active Directory vulnerability. But luckily, there have been no reports of the attack occurring in the wild, according to Microsoft. Alex Matthews and John Guzik of Securify get credit for reporting this vulnerability.

Two DOS flaws affecting all recent versions of Windows have been addressed with Security Bulletin MS08-036. The flaws--called the PGM Invalid Length vulnerability and the PGM Malformed Fragment vulnerability--both have to do with improper validation of pragmatic general multicast (PGM) requests in the operating system. Windows 2000 SP4 is the only Windows OS not affected. Microsoft has no reports of this flaw being exploited in the wild.

1 Moderate Patch

A flaw in Windows' speech recognition engine that could allow an attacker to take full control of an affected computer has been fixed with Security Bulletin MS08-032. While this flaw carries a risk of remote code execution, Microsoft gave it a moderate rating because so few people actually use the speech recognition feature in Windows. In fact, many of you may be surprised to learn that Windows has a speech recognition feature (it doesn't work very well). In any case, this patch provides a killbit for that feature.

MS08-32 is also the only patch from yesterday that addresses an issue that had been previously disclosed to the public. However, nobody has been victimized by attackers utilizing the flaw, to the best of Microsoft's knowledge, it says.

Expert Advice

So there you have it--the latest batch of patches for your varied Windows flaws. So what do you do now? According to security experts, you should start patching.

"Organizations should not be lax when rolling out this month's patches as they have the potential to create widespread hacks," says Paul Zimski, vice president security solutions at Lumension Security, a provider of patch management software for Windows.

Two patches that stand out in particular to Zimski are the ones affecting Bluetooth and Active Directory. The Bluetooth problem could "mean that it's possible to attack a victim's computer just by being within close proximity and not actually being on the network itself," he says. Also, due to Active Directory's widespread use, administrators should pay special attention to this flaw, he says.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
STORAGE GUARDIAN

For a limited, Storage Guardian is offering
our remote backup services at a rate of
$8/compressed GB/month (based on a
3:1 compression ratio) with
No Minimum GB/month Commitment.

                                            · Backup System State / Active Directory
                                            · SQL, MS Exchange, .PST files "Open & Locked"
                                            · Bare Metal Restore

Get your estimate NOW at:
www.storageguardian.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2009 conference, April 26 - April 30, in Reno, Nevada
MoshiMoshi:  An Interactive Experience for the System i Community. See Episode 1 now!
Storage Guardian:  Remote backup services at a special rate of $8/compressed GB/month

 

 

IT Jungle Store Top Book Picks

Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
The Power Systems M15 and M25 Versus Their Predecessors

Forget About Platforms, Let's Talk About Jobs

Zend Taps System i-PHP Guru, Pushes the i Platform

As I See It: Citizen CEO

Imtech Buys Reseller Real Solutions for U.K. Expansion

The Linux Beacon
How's Red Hat Enterprise Linux 5 Doing?

AMD Finishes Off Quad Cores with Budapest Opterons

Forget About Platforms, Let's Talk About Jobs

As I See It: Citizen CEO

Looks Like Unisys Is Reselling Sun's X4600 Opteron Boxes

Four Hundred Stuff
Bank's Approach to Biometric Authentication a 'Valid' One

Programmer Conveniences Added to BCD's WebSmart ILE

ASNA Brings RPG to .NET Migration Software to Latest Windows IDE

Safestone Re-emerges with New Corporate Identity, i OS Security Tools

NetManage and HiT Software Partner for Structured Data

Big Iron
The Back and Forth of the PSI-IBM Lawsuit

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Exploring the DB2 for i5/OS Extensions to the PHP Language

Use Parameter Markers in SQL Persistent Stored Modules

Admin Alert: Quick Audits for i5/OS Backups

System i PTF Guide
June 7, 2008: Volume 10, Number 23

May 31, 2008: Volume 10, Number 22

May 24, 2008: Volume 10, Number 21

May 17, 2008: Volume 10, Number 20

May 10, 2008: Volume 10, Number 19

May 3, 2008: Volume 10, Number 18

The Unix Guardian
AMD Finishes Off Quad Cores with Budapest Opterons

U.S. Drags Down Server Sales in Q1, But Weak Dollar Helps

Looks Like Unisys Is Reselling Sun's X4600 Opteron Boxes

Themis Partners with Sun to Make Sparc T2 Blade Server

Server Branding 101: Big Name, Big Game?

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

IT Security
Storage Guardian
Danik Consulting
World Data Products
MKS


Printer Friendly Version


TABLE OF CONTENTS
Muglia Leads Off Week Two of Tech Ed

Fixes for Critical Security Flaws Issued by Microsoft

New Windows Clustering Capability Has HA Partners Shifting Gears

Stratus Builds Its First HA Clustering Product Atop Xen

Icahn Pushes Micro-Hoo in a Series of Letters

But Wait, There's More:

Magic Targets Rich Internet Apps, SaaS with G5 . . . AMD Finishes Off Quad Cores with Budapest Opterons . . . Looks Like Unisys Is Reselling Sun's X4600 Opteron Boxes . . . There's Still Money in Operating Systems, But Disruptions Loom . . . NOAA Predicts the 2008 Hurricane Season to Be an Active One . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement