RealPlayer is prone to an unspecified buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer. A remote attacker may exploit this vulnerability by presenting a malicious file to a victim and enticing them to open it with the vulnerable application. Successful exploits can allow attackers to run arbitrary code in the context of the user running the affected application. Failed attacks will likely cause denial-of-service conditions. This issue affects RealPlayer 11; other versions may also be affected. More @ poweredlink.blogspot.com
1. ClamAV 'libclamav/pe.c' MEW Packed PE File Integer Overflow Vulnerability Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26927 Summary: ClamAV is prone to an integer-overflow vulnerability because it fails to properly verify user-supplied data.
Successful exploits of this vulnerability can allow remote attackers to execute arbitrary machine code in the context of applications using the 'libclamav' library. Failed exploits may crash the application. ClamAV 0.91.2 is vulnerable to this issue; other versions may also be affected.
2. Retired: Adobe Flash Player Multiple Security Vulnerabilities Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26929 Summary: Adobe Flash Player is prone to multiple security vulnerabilities. The following individual records have been created to document these vulnerabilities:
Adobe Flash Player ActiveX Control 'navigateToURL' API Cross Domain Scripting Vulnerability Adobe Flash Player JPG Header Remote Heap Based Buffer Overflow Vulnerability Adobe Flash Player 'asfunction' Cross Site Scripting Vulnerability Adobe Flash Player Unspecified Privilege-Escalation Vulnerability Adobe Flash Player HTTP Response Splitting Vulnerability Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
These issues affect Adobe Flash Player 9.0.48.0, 8.0.35.0, 7.0.70.0 and prior versions.
3. Adobe Flash Player DNS Rebinding Vulnerability Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26930 Summary: Adobe Flash Player is prone to a DNS rebinding vulnerability that allows remote attackers to establish arbitrary TCP sessions.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious SWF file. Successfully exploiting this issue allows the attacker to bypass the application's same-origin policy and set up connections to services on arbitrary computers. This may lead to other attacks.
4. libexif Image Tag Remote Integer Overflow Vulnerability Remote: Yes Date Published: 2007-12-19 Relevant URL: http://www.securityfocus.com/bid/26942 Summary: The libexif library is prone to an integer-overflow vulnerability because the software fails to ensure that integer values are not overrun.
Successful exploits of this vulnerability allow remote attackers to execute arbitrary machine code in the context of an application using the vulnerable library. Failed attempts will likely result in denial-of-service conditions.
5. Linux Kernel IPv6 Hop-By-Hop Header Remote Denial of Service Vulnerability Remote: Yes Date Published: 2007-12-19 Relevant URL: http://www.securityfocus.com/bid/26943 Summary: The Linux kernel is prone to a remote denial-of-service vulnerability because it fails to adequately validate specially crafted IPv6 'Hop-By-Hop' headers.
Attackers can exploit this issue to cause a kernel panic, denying service to legitimate users.
6. ClamAV 'mspack.c' Off-By-One Buffer Overflow Vulnerability Remote: Yes Date Published: 2007-12-19 Relevant URL: http://www.securityfocus.com/bid/26946 Summary: ClamAV is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to insufficiently sized memory buffers.
Successful exploits of this vulnerability can allow remote attackers to execute arbitrary machine code in the context of applications using the 'libclamav' library. Failed exploits may crash the application.
ClamAV 0.91.2 is vulnerable to this issue; other versions may also be affected.
7. Adobe Flash Player 'asfunction' Cross Site Scripting Vulnerability Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26949 Summary: Adobe Flash Player is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
8. Adobe Flash Player JPG Header Remote Heap Based Buffer Overflow Vulnerability Remote: Yes Date Published: 2007-12-19 Relevant URL: http://www.securityfocus.com/bid/26951 Summary: Adobe Flash Player is prone to a remote heap-based buffer-overflow vulnerability because the application fails to use consistent signedness when handling user-supplied input.
An attacker can exploit this issue to execute arbitrary code with the privileges of a user running the application. Failed exploit attempts will likely cause denial-of-service conditions. This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0, 7.0.70.0, and prior versions.
9. Adobe Flash Player ActiveX Control 'navigateToURL' API Cross Domain Scripting Vulnerability Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26960 Summary: The Adobe Flash Player ActiveX control is prone to a cross-domain scripting vulnerability.
An attacker may leverage this issue to execute arbitrary JavaScript in the context of another domain. This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0, and prior versions.
10. Adobe Flash Player Unspecified Privilege-Escalation Vulnerability Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26965 Summary: Adobe Flash Player is prone to a vulnerability that allows attackers to gain elevated privileges on affected computers.
Very few technical details are currently available. We will update this BID as more information emerges.
NOTE: This issue occurs only when the application is running on a Linux operating system.
Versions prior to Adobe Flash Player 9.0.115.0 are vulnerable.
11. Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability Remote: Yes Date Published: 2007-12-18 Relevant URL: http://www.securityfocus.com/bid/26966 Summary: The Adobe Flash Player is prone to a cross-domain security-bypass vulnerability.
An attacker can exploit this issue to connect to arbitrary hosts on affected computers. This may allow the application to perform generic TCP requests to determine what services are running on the affected computer.
This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0. 7.0.70.0, and prior versions.
12. Adobe Flash Player HTTP Response Splitting Vulnerability Remote: Yes Date Published: 2007-12-20 Relevant URL: http://www.securityfocus.com/bid/26969 Summary: Adobe Flash Player is prone to an HTTP response-splitting vulnerability because it fails to adequately sanitize user-supplied input.
A remote attacker can exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0, and 7.0.70.0 and prior versions.
13. libexif Image Tag Remote Denial Of Service Vulnerability Remote: Yes Date Published: 2007-12-19 Relevant URL: http://www.securityfocus.com/bid/26976 Summary: The libexif library is prone to a denial-of-service vulnerability because of an infinite-recursion error.
Exploiting this issue allows remote attackers to cause denial-of-service conditions in the context of an application using the vulnerable library.
14. Bitflu StorageFarabDb Module '.torrent' File Handling Security Bypass Vulnerability Remote: Yes Date Published: 2007-12-26 Relevant URL: http://www.securityfocus.com/bid/27043 Summary: Bitflu is prone to a security-bypass vulnerability.
An attacker can exploit this issue to append to or create arbitrary files.
This issue affects versions of Bitflu prior to 0.42.
Remote: Yes Date Published: 2007-12-26 Relevant URL: http://www.securityfocus.com/bid/27043 Summary: Bitflu is prone to a security-bypass vulnerability.
An attacker can exploit this issue to append to or create arbitrary files. This issue affects versions of Bitflu prior to 0.42.
16. ClamAV BZ_GET_FAST Bzip2 Decompression Vulnerability Remote: Yes Date Published: 2007-12-29 Relevant URL: http://www.securityfocus.com/bid/27063 Summary: ClamAV is prone to a vulnerability due to a flaw in its Bzip2 decompression support.
Successful exploits of this vulnerability may potentially allow remote attackers to execute arbitrary code in the context of the vulnerable application or to trigger denial-of-service conditions. These affects have not been confirmed.
Further information is not currently available; this BID will be updated as more information is disclosed. ClamAV 0.91.2 is vulnerable to this issue; other versions may also be affected.
The Top 5 Most Overlooked Open Source Vulnerabilities for 2007
For year-end 2007, we have compiled the Top 5 Most Overlooked Open Source Vulnerabilities encountered during 2007. We came up with this list after reviewing over 300 million lines of code and spending literally thousands of hours of analysis across a wide range of industries - including technology, financial services and government, among others.
So what do we mean by "Most Overlooked"? Well first, we mean that these are known vulnerabilities with a high-severity, Common Vulnerability and Exposure, (CVE) ranking found within open source projects that appear in code audits we perform. Secondly, and perhaps even more importantly, these vulnerabilities were found throughout 2007 in some of the most frequently used open source projects that customers did not realize they had.
It's sometimes dangerous to publish a list like this because it can so easily be taken out of context. Let me first stress that open source software is NOT any more vulnerable than commercial software - some folks even point to evidence that it's less vulnerable. The majority of open source projects provide a patched version for issues within hours of discovery.
What does put people at risk, however, is if you don't know that you're using open source components at all. When that's the case, as it so often is, then how can you retrieve the updated versions? When you don't have a system in place to to alert you to available patches or security issues, you put yourself at risk for introducing security vulnerabilities into your organization's code base
So here's our Top 5 Most Overlooked Open Source Vulnerabilities for 2007 in alphabetical order:
PROJECT DESCRIPTION: A free software application server developed by the Apache Software Foundation
VULNERABILITY DESCRIPTION: The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
PROJECT DESCRIPTION: JBoss Application Server (or JBoss AS) is a free software / open source Java EE-based application server.
VULNERABILITY DESCRIPTION: Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the console manager.
PROJECT DESCRIPTION: (Library for reading and writing Tagged Image File Format) (abbreviated TIFF) files. The set also contains command line tools for processing TIFF's. It is distributed in source code and can be found (on the internet) as binary builds for all kinds of platforms. LibTiff is embedded multiple Linux distributions.
VULNERABILITY INFORMATION: TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to pass numeric range checks and possibly execute code, and trigger assert errors, via large offset values in a TIFF directory that lead to an integer overflow and other unspecified vectors involving "unchecked arithmetic operations".
PROJECT DESCRIPTION: Net-SNMP is a suite of software for using and deploying the SNMP protocol (v1, v2c and v3 and the AgentX subagent protocol).
VULNERABILITY INFORMATION: snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177.
PATCH INFORMATION: http://downloads.sourceforge.net/net-snmp/net-snmp-5.4.1.zip?modtime=1185535864&big_mirror=1. This issue has been addressed in the following (and later) versions: 5.1.3, 5.2.2, 5.3
PROJECT DESCRIPTION: Zlib is a software library used for data compression. zlib was written by Jean-loup Gailly and Mark Adler and is an abstraction of the DEFLATE compression algorithm used in their gzip file compression program.
VULNERABILITY INFORMATION: zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
PATCH INFORMATION: Upgrade to version 1.2.3. http://www.zlib.net/zlib-1.2.3.tar.gz
Vulnerabilities do NOT mean that you should avoid using these popular projects. To the contrary, the quick response and patch availability indicates that these are active projects which consider vulnerabilities a serious issue. Take these projects up on their hard work - and make sure you're using the latest stable version.
We're interested in what your versions of the Top Most Overlooked Open Source Vulnerabilities might be!
Description: A vulnerability has been reported in Opera, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an unspecified error when processing JavaScript code and can result in a virtual function call using an invalid pointer. This can be exploited to execute arbitrary code by e.g. tricking a user into visiting a malicious website. The vulnerability is reported in versions prior to 9.23.
Solution: Opera Software has released Opera 9.23, where this issue has been fixed. Update to version 9.23. http://www.opera.com/download/
This vulnerability allows remote attackers to download and remove any file on vulnerable versions of Kaspersky Anti-Virus. User interaction is required to exploit this vulnerability: the user must visit a webpage which takes advantage of this vulnerability. The specific flaw exists within the ActiveX controls in AxKLProd60.dll and AxKLSysInfo.dll
During installation of Maintenance Pack 2, the DLLs will be removed from the system.
Kaspersky Anti Virus SysInfo ActiveX Control Information Disclosure Vulnerability2
The remote exploitation of the information disclosure vulnerability in Kaspersky Anti-Virus 6.0 could allow malicious websites to steal files from end user machine running Kaspersky Anti-Virus.
The SysInfo ActiveX control includes a method called StartUploading which allows malicious web scripts to perform an anonymous FTP transfer of any file the scripts identify on the victim's machine. No dialogs, warnings or user action is required to perform the transfer.
During installation of Maintenance Pack 2, this DLL will be removed from system.
Kaspersky AV Library Remote Heap Overflow1
This vulnerability affected systems which are running the Kaspersky Anti-Virus Engine. User interaction is not required to exploit this vulnerability.
The OnDemand Scanner incorrectly parses specially crafted ARJ archives inside the arj.ppl module. This results in a memory overrun. Most often the product simply crashes. The corruption potentially can be exploited to execute arbitrary code without user interaction. Any products using arj.ppl are vulnerable.
klif.sys Heap Overflow Vulnerability2
Locally executed code can write some special values into registry that hangs klif.sys driver, part of the proactive protection. The driver hooks and screens certain system calls, including registry functions. One of the hook functions is vulnerable to an integer overflow that leads to a kernel heap overflow. If a large unsigned value for the data size argument is passed an arithmetic overflow occurs when the amount of memory to allocate is calculated. A copy operation into this buffer causes a corruption of kernel page pool memory.
KLIF Local Privilege Escalation Vulnerability
This vulnerability allows locally executed code to receive Ring-0 privileges through klif.sys unsafe code. User interaction is required to execute the code. The vulnerability is local and code should first appear on user's computer.
All these vulnerabilities have been fixed in the build 6.0.2. 614.
1 Kaspersky would like to thank an anonymous researcher working with TippingPoint (www.tippingpoint.com) and the Zero Day Initiative (www.zerodayinitiative.com) for reporting this issue.
attachment spoofing in Mozilla Thunderbird SecuriTeam has reported a vulnerability that lies in the way that the mail reader Mozilla Thunderbird displays attachments, which allows an attacker to spoof them. The security flaw in Mozilla Thunderbird occurs because attached files are displayed incorrectly in messages. This flaw can be used to spoof the extension and icon associated to the file using a combination of over long names with blank spaces and Content-Type headers that do not correspond to the file extension. An attacker who successfully exploited this vulnerability could save malicious files to the desktop. Users of Mozilla Thunderbird are recommended to update by installing version 1.5, which is not affected by this security problem.