| Threat Type | Multiple Vulnerabilities |
IPS Definition DB Versions | 2.531 - 2.537 |
| Coverage Release Date | Aug 08, 2008 - Aug 19, 2008 |
| Published Date | Wednesday, August 20, 2008 |
| Version # | 1 |
| |
| Severity | Number of Vulnerabilities | Active Exploitation |
| Critical | 18 | 4 | | High | 21 | 7 | | Medium | 13 | 2 | | Low | 5 | 2 | | Info | 1 | n/a | | Total | 58 | 15 |
|
Foreword
The FortiGuard Global Threat Research Team has released new security content to cover multiple vulnerabilities. The FortiGuard Team has observed 15 active exploitations of these vulnerabilities to date.
For more information, visit the FortiGuard Center at www.fortiguardcenter.com.
Threat Remediation
Fortinet provides coverage for the vulnerabilities described below as of the 2.537 IPS Definitions database update. A brief description of each vulnerability is provided as follows, in order of severity.
Critical ( 16 )
Description: This indicates an attempt to exploit a buffer-overflow vulnerability in Adobe Photoshop Album Starter Edition.
This vulnerability is caused by a boundary condition error when parsing malformed BMP images. An attacker may exploit this to execute arbitrary code, or cause denial of service.
Affected Products: Adobe Photoshop Album Starter 3.2 Adobe After Effects CS3 0
Reference IDs:
|
Description: This indicates an attempt to exploit a stack-based vulnerability in CA eTrust Secure Content Manager.
This vulnerability may cause a buffer overflow when responding to overly long LIST commands via FTP. A remote attacker may exploit this to execute arbitrary code or cause denial of service.
Affected Products: CA eTrust Secure Content Manager 8.0.
Reference IDs:
|
Description: This indicates an attack attempt against a buffer-overflow vulnerability in Microsoft DirectX. The vulnerability is caused by an error when the vulnerable software handles crafted MJPEG streams. It allows a remote attacker to execute arbitrary code by sending a crafted AVI file.
Affected Products: Microsoft DirectX 9.0b Microsoft DirectX 9.0 c Microsoft DirectX 9.0 a Microsoft DirectX 9.0 Microsoft DirectX 8.1 b Microsoft DirectX 8.1 a Microsoft DirectX 8.1 Microsoft DirectX 10.0
Reference IDs:
|
Description: This indicates an attack attempt towards a memory corruption vulnerability In Microsoft Internet Explorer.
The vulnerability is caused by accessing uninitialized memory in certain situations. An attacker may exploit this to cause denial of service or remote code execution.
Affected Products: Microsoft Internet Explorer 6 Microsoft Internet Explorer 7
Reference IDs:
|
Description: This indicates an attack attempt against a memory-corruption vulnerability in Microsoft Internet Explorer.
The vulnerability is due to an integer addition overflow in the TextRange object when storing text strings. A remote attacker may exploit this to cause the application to crash or to execute arbitrary code.
Affected Products: Internet Explorer 5.01 Service Pack 4 when installed on Microsoft Windows 2000 Service Pack 4 Internet Explorer 6 Internet Explorer 7
Reference IDs:
|
Description: This indicates an attempt to exploit a remote code-execution vulnerability in Microsoft Internet Explorer.
The vulnerability is due to the application's inability to properly parse a malformed web page. A successful exploit may allow execution of arbitrary code.
Affected Products: Microsoft Internet Explorer 7 Microsoft Internet Explorer 6 Service Pack 1 Microsoft Internet Explorer 6 Microsoft Internet Explorer 5.01 Service Pack 4 Microsoft Internet Explorer 5.01
Reference IDs:
|
Description: This indicates an attack attempt towards a memory corruption vulnerability in Internet Explorer. The memory corruption occurs when the Internet Explorer attempts to access uninitialized memory in certain situations. This could lead to a crash of the Internet Explorer or to remote code execution.
Affected Products: Internet Explorer 5.01 Service Pack 4 when installed on Microsoft Windows 2000 Service Pack 4 Internet Explorer 6 Internet Explorer 7
Reference IDs:
|
Description: This indicates an attack attempt against a double-free memory-corruption vulnerability in Microsoft Internet Explorer.
The vulnerability is due to the way the application manages certain HTTP responses. It could lead to a crash in the Internet Explorer or to remote code execution.
Affected Products: Internet Explorer 5.01 Service Pack 4 when installed on Microsoft Windows 2000 Service Pack 4 Internet Explorer 6 Internet Explorer 7
Reference IDs:
|
Description: This indicates an attack attempt against a buffer overflow vulnerability in Microsoft Office Filters. The vulnerability is caused by an error that occurs when the vulnerable software handles a malicious Apple PICT / QuickDraw image file. It allows a remote attacker to execute arbitrary code by luring the victim to import the file in Office documents.
Affected Products: Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office Project 2002 Service Pack 1 Microsoft Office Converter Pack Microsoft Works 8
Reference IDs:
|
Description: This indicates a possible attempt to exploit a heap corruption vulnerability in Microsoft Office.
The vulnerability is caused by an error that occurs when the vulnerable software handles an imported PICT file. A remote attacker may exploit this to execute arbitrary code via a crafted PICT file.
Affected Products: Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office Project 2002 Service Pack 1 Microsoft Office Converter Pack Microsoft Works 8
Reference IDs:
|
Description: This indicates an attempt to exploit a code-execution vulnerability in Microsoft Office Word.
The vulnerability is caused by an error when the vulnerable software handles a crafted .doc file. It allows a remote attacker to execute arbitrary code.
Affected Products: Microsoft Office XP Microsoft Word 2002
Reference IDs:
|
Description: This indicates a possible attempt to exploit a remote code-execution vulnerability in Microsoft PowerPoint.
The vulnerability is caused by an error when the vulnerable software handles a malformed .PPT file. It allows a remote attacker to execute arbitrary code via sending a crafted .PPT file.
Affected Products: Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office 2003 Service Pack 3 2007 Microsoft Office System 2007 Microsoft Office System Service Pack 1
Reference IDs:
|
Description: This indicates a possible attempt to exploit a remote code-execution vulnerability in Microsoft PowerPoint.
The vulnerability is caused by an error when the vulnerable software handles a malformed .PPT file. It allows a remote attacker to execute arbitrary code via sending a crafted .PPT file.
Affected Products: Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office 2003 Service Pack 3 2007 Microsoft Office System 2007 Microsoft Office System Service Pack 1
Reference IDs:
|
Description: This indicates a possible attempt to exploit a remote code-execution vulnerability in Microsoft PowerPoint.
The vulnerability is caused by an error that occurs when the vulnerable software handles a malformed .PPT file. It allows a remote attacker to execute arbitrary code via sending a crafted .PPT.
Affected Products: Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office 2003 Service Pack 3 2007 Microsoft Office System 2007 Microsoft Office System Service Pack 1
Reference IDs:
|
Description: This indicates an attempt to exploit a heap-overflow vulnerability in the Microsoft Color Management System.
The vulnerability is due to a flaw in the processing of malformed EMF files, which may lead to a crash or a remote code execution in the context of the current process.
Affected Products: Microsoft Windows 2000 Service Pack 4 Windows XP Service Pack 2 and Windows XP Service Pack 3 Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
Reference IDs:
|
Description: This indicates a possible attempt to exploit a buffer-overflow vulnerability in Trend Micro OfficeScan.
The vulnerability is located in the "OfficeScanRemoveCtrl.dll" ActiveX control through misuse of the "Sever" property. It may allow remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely cause the program to crash, resulting in a denial-of-service condition.
Affected Products: OfficeScan 7.3 patch 4 OfficeScanRemoveCtrl.dll version 7.3.0.1020
Reference IDs:
|
High ( 10 )
Description: This indicates an attack attempt against a buffer-overflow vulnerability in Computer Associates eTrust Secure Content Manager. The vulnerability is caused by an error when the vulnerable software handles a malicious PASV response packet. It allows a remote attacker to execute arbitrary code by sending a crafted FTP response packet.
Affected Products: Computer Associates eTrust Secure Content Manager 8.0
Reference IDs:
|
Description: This indicates a possible attempt to exploit an authentication-bypass issue in Cisco IOS FTP Server.
This vulnerability affects only those IOS devices that are configured to have the IOS FTP Server enabled. An attacker may exploit this issue to execute arbitrary code or cause denial-of-service conditions.
Affected Products: IOS 12.3(18) on 2621XM router
Reference IDs:
|
Description: This indicates an attempt to exploit a buffer-overflow vulnerability in IBM Lotus Domino.
This vulnerability is caused by the Web Server service's inability to check user-supplied input. A remote attacker may send an HTTP request with an overly long "Accept-Language" header, causing the affected to server to crash or possibly execute arbitrary code.
Affected Products: IBM Lotus Domino 7.0.3 IBM Lotus Domino 7.0 IBM Lotus Domino 6.5 .0 IBM Lotus Domino 6.0 IBM Lotus Domino 8.0
Reference IDs:
|
Description: This indicates an attempt to exploit an SQL injection vulnerability through HTTP requests.
The vulnerability is a result of the application's failure to check user input before using it in an SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server.
Affected Products: N/A
|
Description: This indicates a possible attempt to exploit a memory corruption vulnerability in Microsoft Internet Explorer.
Affected Products: Microsoft Internet Explorer 7 Microsoft Internet Explorer 6 Service Pack 1 Microsoft Internet Explorer 6 Microsoft Internet Explorer 5.01 Service Pack 4 Microsoft Internet Explorer 5.01
Reference IDs:
|
Description: This indicates an attack attempt against a buffer overflow vulnerability in Microsoft Office Filters. The vulnerability is caused by an error when the vulnerable software handles a malicious WordPerfect Graphics (WPG) image file. It allows a remote attacker to execute arbitrary code by luring the victim to import the file in Office documents.
Affected Products: Microsoft Office 2000 Service Pack 3 Microsoft Office XP Service Pack 3 Microsoft Office 2003 Service Pack 2 Microsoft Office Project 2002 Service Pack 1 Microsoft Office Converter Pack Microsoft Works 8
Reference IDs:
|
Description: This indicates an attack attempt against a remote code execution vulnerability in the Microsoft Windows Event System. The vulnerability is caused by incorrectly validating user subscriptions. It allows a remote attacker to execute arbitrary code by hooking a subscription to an event.
Affected Products: Microsoft Windows 2000 Service Pack 4 Windows XP Service Pack 2 and Windows XP Service Pack 3 Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 Windows Server 2003 x64 Edition and Windows 2003 Server x64 Edition Service Pack 2 Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium based Systems Windows Vista and Windows Vista Service Pack 1 Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1 Windows Server 2008 for 32-bit Systems Windows Server 2008 for x64-based Systems Windows Server 2008 for Itanium-based Systems
Reference IDs:
|
Description: This indicates an attempt to exploit a buffer-overflow vulnerability in Oracle Database product.
The vulnerability is caused by inadequate checking of the parameters passed to some procedures in the DBMS_AQELM package. It allows remote attackers to execute arbitrary code by calling this procedure with long arguments.
Affected Products: Oracle Database 9.2.0.8 Oracle Database 9.2.0.8DV Oracle Database 10.1.0.5 Oracle Database 10.2.0.4 Oracle Database 11.1.0.6
Reference IDs:
|
Description: This indicates an attempt to exploit a command-injection vulnerability in SpamAssassin.
The vulnerability is caused by the lack of adequate checking when the vulnerable software handles some fields in the protocol for communication between spamc/spamd. It allows a remote attacker to inject arbitrary commands by sending a crafted request.
Affected Products: SpamAssassin 3.1.2 and prior
Reference IDs:
|
Description: This indicates an attempt to exploit a buffer-overflow vulnerability in the X.Org Foundation's X Windows Server.
The vulnerability is caused by a boundary error when processing a malformed PCF Font. It allows a remote attacker to execute arbitrary code via sending a crafted PCF Font file.
Affected Products: X.org Xserver 1.3 X.org xorg-server 1.4 X.org xorg-server 1.3.99.2 (RC2) X.org xorg-server 1.2 X.org xorg-server 1.02-r5 X.org xorg-server 1.0.2-r6 X.org X11R7 1.1.1 X.org X11R7 1.0.2 X.org X11R7 1.0.1 X.org X11R7 1.0 X.org X11R7 7.2 X.org X11R7 7.1 X.org X11R7 7.0 X.org X11R6 6.9 X.org X11R6 6.8.2 X.org X11R6 6.8.1 X.org X11R6 6.8 X.org X11R6 6.7 .0 X.org X11R6 5.1 X.org X11R6 4.0 X.org LibXfont 1.3.
Reference IDs:
|
Medium ( 8 )
Description: This indicates an attempt to exploit a memory-corruption vulnerability in Alt-N Technologies MDaemon WorldClient.
The vulnerability is caused by a NULL-pointer dereference error in processing a malicious HTTP POST request. A remote attacker may exploit this to cause a denial-of-service condition.
Affected Products: Alt-N, MDaemon, 9.6.5, and previous
Reference IDs:
|
Description: This indicates an attempt to exploit a denial-of-service vulnerability in CA ARCserve Backup Discovery service.
The vulnerability is by an input-validation error in casdscsvc.exe. A remote unauthenticated attacker may crash the target server by sending a malformed message.
Affected Products: Computer Associates Server Protection Suite r2 SP1 Computer Associates Server Protection Suite r2 Computer Associates Protection Suites r2 0 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup 11.5.SP3 Computer Associates BrightStor ARCServe Backup 11.5.SP2 Computer Associates BrightStor ARCServe Backup 11.5.SP1 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates ARCserve Backup 12.0.5454 .0
Reference IDs:
|
Description: This indicates an attempt to exploit a buffer-overflow vulnerability in CUPS.
The vulnerability is caused by a boundary error in the handling of malformed GIF files and may be exploited by remote attackers to compromise a vulnerable system or cause denial of service.
Affected Products: Ubuntu Ubuntu Linux 7.10 Ubuntu Ubuntu Linux 7.04 Ubuntu Ubuntu Linux 6.10 Ubuntu Ubuntu Linux 6.06 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux Turbolinux Server 10.0.0 x64 TurboLinux Personal TurboLinux Multimedia Turbolinux FUJI 0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 3.0 x64 Turbolinux Appliance Server 3.0 Turbolinux Appliance Server 2.0 Slackware Linux 12.0 S.u.S.E. SUSE Linux Enterprise Server 10 SP1 S.u.S.E. SUSE Linux Enterprise Desktop 10 SP1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 RedHat Fedora 8 0 RedHat Fedora 7 0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop 5 client RedHat Enterprise Linux AS 4 RedHat Enterprise Linux AS 3 RedHat Enterprise Linux 5 server RedHat Desktop 4.0 RedHat Desktop 3.0 MandrakeSoft Linux Mandrake 2008.0 x86_64 MandrakeSoft Linux Mandrake 2008.0 MandrakeSoft Linux Mandrake 2007.1 x86_64 MandrakeSoft Linux Mandrake 2007.1 MandrakeSoft Linux Mandrake 2007.0 x86_64 MandrakeSoft Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo net-print/cups 1.2.12-r6 Easy Software Products CUPS 1.3.6
Reference IDs:
|
Description: This indicates an attempt to exploit an information-disclosure vulnerability in Microsoft IE.
The vulnerability is caused by some errors in the implementation of XMLHttpRequest. An attacker can overwrite the "Host" and other HTTP header fields by using some insecure methods of XMLHttpRequest object. It allows remote attackers to steal private information by tricking a user into viewing a malicious web page which calls these insecure methods.
Affected Products: Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 SP4 Internet Explorer 6 SP1 when installed on Microsoft Windows 2000 SP4 Internet Explorer 6 for Windows XP SP2 and SP3 Internet Explorer 6 for Windows XP Professional x64 Edition and SP2 Internet Explorer 6 for Windows Server 2003 SP1 and SP2 Internet Explorer 6 for Windows Server 2003 x64 Edition and SP2 Internet Explorer 6 for Windows Server 2003 with SP1 for Itanium-based Systems and SP2 Internet Explorer 7 for Windows XP SP2 and SP3 Internet Explorer 7 for Windows XP Professional x64 Edition and SP2 Internet Explorer 7 for Windows Server 2003 SP1 and SP2 Internet Explorer 7 for Windows Server 2003 x64 Edition and SP2 Internet Explorer 7 for Windows Server 2003 with SP1 for Itanium-based Systems and SP2 Internet Explorer 7 in Windows Vista and Internet Explorer 7 in Windows Vista SP1 Internet Explorer 7 in Windows Vista x64 Edition and SP1 Internet Explorer 7 in Windows Server 2008 for 32-bit Systems Internet Explorer 7 in Windows Server 2008 for x64-based Systems Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems
Reference IDs:
|
Description: This indicates an attempt to exploit multiple information disclosure vulnerabilities in Microsoft Windows Live Messenger.
With the information that is disclosed, a malicious attacker can control the local Live Messenger. The exploit also reveals personal information from Live Messenger and makes it possible to transfer local audio and video information to a remote location.
Affected Products: Windows Messenger 4.7 Windows Messenger 5.1
Reference IDs:
|
Description: This indicates a possible attempt to exploit an information-disclosure vulnerability in Microsoft Outlook Express.
The vulnerability is due to an error in Windows MHTML protocol handler. An attacker may exploit this to bypass security restrictions and access data on the vulnerable computer.
Affected Products: Microsoft Outlook Express 6 Service Pack 1 Microsoft Outlook Express 6 Microsoft Outlook Express 5.5 Service Pack 2
Reference IDs:
|
Description: This indicates an attempt to exploit a buffer-overflow vulnerability in the Novell iPrint Client ActiveX control.
The vulnerability is caused by a boundary checking error when certain parameters are passed to the affected ActiveX control. Attackers may exploit this to execute arbitrary code.
Affected Products: Novell iPrint Client 'ienipp.ocx' ActiveX control 4.34 Novell iPrint Client 'ienipp.ocx' ActiveX control 4.32 Novell iPrint Client 'ienipp.ocx' ActiveX control 4.26 Novell iPrint Client 4.34
Reference IDs:
|
Description: This indicates an attempt to exploit a denial-of-service vulnerability in OpenLDAP slapd.
The vulnerability is caused by a design error when decoding ASN.1 BER network messages. A remote attacker may exploit this to crash affected systems, creating a denial-of-service condition.
Affected Products: OpenLDAP, 2.3.41 OpenLDAP, 2.3.42
Reference IDs:
|
Low ( 2 )
Description: This indicates an attempt to exploit a denial-of-service vulnerability in IBM Lotus Domino Web Access.
The vulnerability is caused by an out-of-memory error when opening a malicious email containing a large message body.
Affected Products: IBM Lotus Domino 6.5.2 IBM Lotus Domino 6.5.1 IBM Lotus Domino 6.5 .0 IBM Lotus Domino 6.0.3 IBM Lotus Domino 6.0.2 CF2 IBM Lotus Domino 6.0.2 IBM Lotus Domino 6.0.1 IBM Lotus Domino 6.0
Reference IDs:
|
Description: This indicates an attempt to exploit a denial-of-service vulnerability in Kerberos.
The vulnerability is caused by a double-free error in the "krb5_recvauth()" function. An unauthenticated remote attacker can exploit this vulnerability to cause a denial of service.
Affected Products: Kerberos 5.x
Reference IDs:
|
Info ( 1 )
Description: This indicates detection of Facebook Chat data traffic.
Facebook Chat is a free web-based interface to Facebook.com.
Affected Products: Facebook Chat
Reference IDs:
|
Top of Section
Enhanced Coverage
The FortiGuard Threat Research team updates security content as new vectors of exploitation are discovered. The table below details the security content enhanced with this release.
Critical ( 11 )
High ( 26 )
Medium ( 16 )
Low ( 5 )
Top of Section
Active Exploitation
The FortiGuard Threat Research team uses globally distributed probes to monitor exploit activity. Vulnerabilities can be classified as active and given a magnitude level. The magnitude level is the rate of activity across the probes. The value of the magnitude is set to low, medium or high.
The table below lists the vulnerabilities discussed in this bulletin (specifically new and enhanced detection) and their corresponding exploit activity magnitude. The data below is as of this writing.
Critical ( 4 of 18 )
High ( 3 of 11 )
Medium ( 1 of 8 )
Low ( 1 of 3 )
Top of Section
Document History
| Revision Date | Version Number | |
| Wednesday, August 20, 2008 | 1 | Initial Documentation. |
About Fortinet ( www.fortinet.com )
Fortinet is the pioneer and leading provider of ASIC-accelerated unified threat management, or UTM, security systems, which are used by enterprises and service providers to increase their security while reducing total operating costs. Fortinet solutions were built from the ground up to integrate multiple levels of security protection--including firewall, antivirus, intrusion prevention, VPN, spyware prevention and anti-spam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in six programs by ICSA Labs: (Firewall, Antivirus, IPSec, SSL, Network IPS, and Anti-Spyware). Fortinet is privately held and based in Sunnyvale, California.
Disclaimer
Although Fortinet has attempted to provide accurate information in these materials, Fortinet assumes no legal responsibility for the accuracy or completeness of the information. Please note that no Fortinet statements herein constitute or contain any guarantee, warranty or legally binding representation. All materials contained in this publication are subject to change without notice, and Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice.
Top of page
|