New Vulnerability Coverage
| Threat Type: |
Multiple Vulnerabilities |
IPS Definition Database Versions: |
2.514 - 2.517 |
| Coverage Release Date: |
Jun 16, 2008 - Jun 26, 2008 |
| Published Date: |
Friday, June 27, 2008 |
| Version #: |
1 |
| |
| Severity |
Number of Vulnerabilities |
Active Exploitation |
| Critical | 6 | 1 |
| High | 6 | 4 |
| Medium | 3 | 1 |
| Low | - | - |
| Info | - | n/a |
| Total | 15 | 6 |
|
Foreword
The FortiGuard Global Threat Research Team has released new security content to cover
multiple vulnerabilities. The FortiGuard Team has observed
6 active exploitations of these vulnerabilities to date.
For more information, visit the FortiGuard Center at
www.fortiguardcenter.com.
Threat Remediation
Fortinet provides coverage for the vulnerabilities described below as of the
2.517 IPS Definitions database update.
A brief description of each vulnerability is provided as follows, in order of severity.
Critical ( 4 )
Description:
This indicates an attempt to exploit a buffer-overflow vulnerability in BrightStor ARCServe Backup running under Linux.
The vulnerability is caused by a username parameter length-check error in libas6script.so. It allows a remote attacker to execute arbitrary code on the victim's system by sending an excessively long username parameter.
Affected Products:
CA BrightStor ARCServe Backup 11.0 CA BrightStor ARCServe Backup 11.1 CA BrightStor ARCServe Backup 11.5
Reference IDs:
|
Description:
This indicates a vulnerability in CA products, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
Affected Products:
Computer Associates Unicenter Software Delivery 11.2a Computer Associates Unicenter Software Delivery 11.2 C2 Computer Associates Unicenter Software Delivery 11.2 C1 Computer Associates Unicenter Software Delivery 11.2 Computer Associates Unicenter Software Delivery 11.1a Computer Associates Unicenter Software Delivery 11.1 GA Computer Associates Unicenter Software Delivery 11.1 C1 Computer Associates Unicenter Software Delivery 11.1 Computer Associates Unicenter Remote Control 11.2a Computer Associates Unicenter Remote Control 11.2 C2 Computer Associates Unicenter Remote Control 11.2 C1 Computer Associates Unicenter Remote Control 11.2 Computer Associates Unicenter Remote Control 11.1a Computer Associates Unicenter Remote Control 11.1 GA Computer Associates Unicenter Remote Control 11.1 Computer Associates Unicenter Desktop Management Bundle 11.2a Computer Associates Unicenter Desktop Management Bundle 11.2 C2 Computer Associates Unicenter Desktop Management Bundle 11.2 C1 Computer Associates Unicenter Desktop Management Bundle 11.2 Computer Associates Unicenter Desktop Management Bundle 11.1a Computer Associates Unicenter Desktop Management Bundle 11.1 GA Computer Associates Unicenter Desktop Management Bundle 11.1 C1 Computer Associates Unicenter Desktop Management Bundle 11.1 Computer Associates Unicenter Asset Management 11.2a Computer Associates Unicenter Asset Management 11.2 C1 Computer Associates Unicenter Asset Management 11.2 Computer Associates Unicenter Asset Management 11.1a Computer Associates Unicenter Asset Management 11.1 GA Computer Associates Unicenter Asset Management 11.1 C1 Computer Associates Unicenter Asset Management 11.1 Computer Associates Remote Control 11.1 C1 Computer Associates Desktop Management Suite 11.2a Computer Associates Desktop Management Suite 11.2 C2 Computer Associates Desktop Management Suite 11.2 C1 Computer Associates Desktop Management Suite 11.2 Computer Associates Desktop Management Suite 11.1a Computer Associates Desktop Management Suite 11.1 GA Computer Associates Desktop Management Suite 11.1 C1 Computer Associates Desktop Management Suite 11.1 Computer Associates Desktop and Server Management 11.2a Computer Associates Desktop and Server Management 11.2 C2 Computer Associates Desktop and Server Management 11.2 C1 Computer Associates Desktop and Server Management 11.2 Computer Associates Desktop and Server Management 11.1a Computer Associates Desktop and Server Management 11.1 GA Computer Associates Desktop and Server Management 11.1 C1 Computer Associates ARCserve Backup for Laptops and Desktops 11.5
Reference IDs:
|
Description:
This indicates an attempt to exploit a vulnerability in the WMI Object Broker ActiveX control in Microsoft Visual Studio 2005.
This vulnerability is due to improper access control in the CreateObject function of the ActiveX control. By enticing the victim to visit a malicious web site, an attacker may possibly execute arbitrary code.
Affected Products:
Microsoft Visual Studio 2005 Team Edition for Testers 0 Microsoft Visual Studio 2005 Team Edition for Developers 0 Microsoft Visual Studio 2005 Team Edition for Architects 0 Microsoft Visual Studio 2005 Team Edition 0 Microsoft Visual Studio 2005 Standard Edition 0 Microsoft Visual Studio 2005 Professional Edition 0
Reference IDs:
|
Description:
This indicates a possible attempt to exploit a memory-corruption vulnerability in Xunlei Thunder.
The vulnerability is located in the "DapCtrl" DLL ActiveX control through misuse of the "Put" method. It may allow remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control.
Affected Products:
Thunder 5, DapCtrl.dll 1.5.578.28 and later versions.
|
High ( 5 )
Description:
This indicates an attempt to exploit a buffer overflow vulnerability in Adobe Flash Player.
The heap based buffer overflow vulnerability is a result of errors that occur when handling malformed SWF files with embedded JPG images. As a result a remote attacker may be able to gain control of a vulnerable system.
Affected Products:
Adobe Flash Player 9.0.48.0, 8.0.35.0, 7.0.70.0, and prior versions.
Reference IDs:
|
Description:
This indicates an attempt to exploit a code execution vulnerability in Akamai Download Manager.
The vulnerability is caused by a design error in DownloadManager Control while processing two undocumented object parameters. It allows remote attackers to execute arbitrary code by tricking the victim into visiting a malicious web page.
Affected Products:
Akamai Akamai Download Manager 2.2.1.0 Akamai Akamai Download Manager 2.2.0.0
Reference IDs:
|
Description:
This indicates an attempt to exploit a combination of vulnerabilities in Apple Safari and all versions of Microsoft Windows XP and Windows Vista.
A successful exploit allows remote attackers to download files to a user's machine and then execute them without prompting.
Affected Products:
Microsoft Windows XP SP2 Microsoft Windows XP SP3 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista Microsoft Windows Vista SP1 Microsoft Windows Vista x64 Edition Microsoft Windows Vista x64 Edition SP1 Internet Explorer 6 for Microsoft Windows XP SP2, Microsoft Windows XP SP3, Microsoft Windows XP Professional x64 Edition, and Microsoft Windows XP Professional x64 Edition SP2 Internet Explorer 7 for Microsoft Windows XP SP2, Microsoft Windows XP SP3, Microsoft Windows XP Professional x64 Edition, and Microsoft Windows XP Professional x64 Edition SP2 Internet Explorer 7 for Microsoft Windows Vista, Microsoft Windows Vista SP1, Microsoft Windows Vista x64 Edition, and Microsoft Windows Vista x64 Edition SP1
Reference IDs:
|
Description:
This indicates an attempt to exploit a buffer-overflow vulnerability in IBM Lotus Sametime.
The IBM Lotus Sametime application contains a stack-based buffer-overflow vulnerability that is triggered when processing malformed HTTP requests. Successful exploitation could make it possible for remote attackers to execute arbitrary code or crash a vulnerable system.
Affected Products:
IBM Lotus Sametime 7.5.1 IBM Lotus Sametime 8.0 IBM Lotus Sametime 7.5 IBM Lotus Sametime 7.0
Reference IDs:
|
Description:
This indicates a potential buffer-overrun exploit of a vulnerability in Winhlp32.exe.
Winhlp32.exe is used by the HTML Help ActiveX control, which ships with Microsoft HTML Help. The vulnerability is a result of insufficient bounds checking of the "Item" parameter in the WinHlp command. This may be exploited to cause denial of service attacks or execution of arbitrary code.
Affected Products:
Microsoft Windows 2000 Microsoft Windows 95 Microsoft Windows 98 Microsoft Windows ME Microsoft Windows NT Microsoft Windows XP
Reference IDs:
|
Medium ( 1 )
Description:
A remote download dialogue box spoofing vulnerability affects Yahoo! Messenger. This issue is due to a design error that facilitates the spoofing of file names.
An attacker may leverage this issue to spoof downloaded file names to unsuspecting users. This issue may lead to a compromise of the target computer as well as other consequences.
Affected Products:
Yahoo! Messenger 6.0.0.1750
Reference IDs:
|
Top of Section
Enhanced Coverage
The FortiGuard Threat Research team updates security content as new
vectors of exploitation are discovered. The table below details the
security content enhanced with this release.
Critical ( 3 )
High ( 1 )
Medium ( 2 )
Top of Section
Active Exploitation
The FortiGuard Threat Research team uses globally distributed probes
to monitor exploit activity. Vulnerabilities can be classified as
active and given a magnitude level. The magnitude level is the rate
of activity across the probes. The value of the magnitude is set to
low, medium or high.
The table below lists the vulnerabilities discussed in this bulletin
and their corresponding exploit activity magnitude. The data below is
as of this writing.
Critical ( 1 of 6 )
High ( 4 of 6 )
Medium ( 1 of 3 )
Top of Section
Document History
| Revision Date |
Version Number |
|
| Friday, June 27, 2008 |
1 |
Initial Documentation. |
About Fortinet ( www.fortinet.com )
Fortinet is the pioneer and leading provider of ASIC-accelerated unified threat management, or UTM, security systems, which are used by enterprises and service providers to increase their security while reducing total operating costs. Fortinet solutions were built from the ground up to integrate multiple levels of security protection--including firewall, antivirus, intrusion prevention, VPN, spyware prevention and anti-spam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in six programs by ICSA Labs: (Firewall, Antivirus, IPSec, SSL, Network IPS, and Anti-Spyware). Fortinet is privately held and based in Sunnyvale, California.
Disclaimer
Although Fortinet has attempted to provide accurate information in these materials, Fortinet assumes no legal responsibility for the accuracy or completeness of the information. Please note that no Fortinet statements herein constitute or contain any guarantee, warranty or legally binding representation. All materials contained in this publication are subject to change without notice, and Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice.
Top of page
|