internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

MS Patch Barrage Comes with IE Fix
Cornucopia of Security Patches Released
Jim Wagner and Ryan Naraine

Microsoft Tuesday released its October batch of security advisories with a slew of "critical" patches, including a monster fix for the Internet Explorer browser.

In all, the software giant issued 10 advisories, seven rated "critical" and three with the lower "important" rating.

In addition, Microsoft re-released the MS04-028 bulletin to correct newly discovered issues for customers running Windows XP Service Pack 2 (SP2). The updated MS04-028 advisory covers JPEG Parsing (GDI+) in Windows, Office, and other graphics programs, and comes at a time when active exploits are already making the rounds.

The most notable fix released Tuesday (download MS04-038) covers known holes in the IE browser, and Microsoft warned that active exploits are already targeting Windows users. The cumulative IE patch includes a fix for a CSS Heap Memory Corruption flaw that could allow remote code execution; a name redirection flaw that would give an attacker access to a susceptible PC, and a drag-and-drop vulnerability that gives malicious hackers complete control of an affected system.

Information on the drag-and-drop weakness, which affects IE versions 5.01, 5.5, and 6.0 on Microsoft Windows XP SP1 or SP2, has been available for nearly two months.

The IE patch also includes a fix for an Install Engine vulnerability, two separate flaws that could lead to address bar spoofing, an SSL caching weakness, and a privilege elevation vulnerability in the way IE processes scripts in image tags.

Microsoft issued another critical alert (download MS04-034) to plug a remote code execution bug in the way that Windows processes Compressed (zipped) Folders. Microsoft warned that a successful exploit could let an attacker take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges.

Windows Server 2003 SMTP Component

The company also released a fix download MS04-035) for a code execution flaw in the way the Windows Server 2003 SMTP component handles Domain Name System (DNS) lookups.

"An attacker could exploit the vulnerability by causing the server to process a particular DNS response that could potentially allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system," Microsoft warned.

The "critical" SMTP bug also exists in the Microsoft Exchange Server 2003 Routing Engine component when installed on Microsoft Windows 2000 Service Pack 3 or on Microsoft Windows 2000 Service Pack 4.

A separate patch with a "critical" rating download MS04-036) was also issued for a remote code execution vulnerability, the Network News Transfer Protocol (NNTP) component used in Microsoft Windows or Microsoft Exchange Server.

Microsoft said the NNTP hole could allow an attacker to construct a malicious request to launch harmful code and take over a user's PC.

Download MS04-037 was also released to cover two holes in Windows Shell that could lead to harmful code execution. It corrects the way that the Windows Shell starts applications, and it corrects a bug in the way specially crafted requests are handled in the Program Group Converter.

The company's Office Excel product suite was also patched to protect against a remote code execution vulnerability. Affected users can find the MS04-033 advisory here.

Windows Kernel Flaw

Another "critical" released Tuesday covers a remote execution code vulnerability in all versions of Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003. The patch corrects four flaws and replaces existing patches for window management, virtual DOS machine, Windows kernel, and graphics rendering engine vulnerabilities released earlier by Microsoft.

The virtual DOS machine and window management breaches are both privilege elevation vulnerabilities, meaning attackers could gain administrative rights to an entire group of computers in the network. From there, they could add new users, delete others, install software, or delete files in the network. The graphics engine vulnerability is a remote code execution flaw that attacks through Windows metafile and enhanced metafile images, and gives the cracker complete control of the system.

The kernel flaw allows the malicious code to launch a Denial-of-Service (DoS) attack (define) on the system's resources, causing the machine to stop responding. A fix for the four flaws, broken down by operating system type, can be downloaded here.

Microsoft had to restrict some of the functionality in the Internet standard Web-based Distributed Authoring and Versioning (WebDAV) requests to plug a vulnerability that allowed malware to consume all available memory and CPU time on an affected server, according to the company's alert.

Security officials discovered that WebDAV — a set of extensions in HTTP (an Internet standard with the IETF) for file collaboration on remote servers — doesn't put a limit on the number of attributes that can be passed to the server, thus allowing the malicious coder room to execute a DoS attack.

Microsoft officials imposed new limits on WebDAV, which will cause previously valid requests to fail. The vulnerability affects Internet Information Services 5.0/5.1/6.0 users and several versions of Windows XP/2000/2003. Users can download the patch here.

Microsoft also fixed a separate code execution flaw in its venerable Network Dynamic Data Exchange (NetDDE), which allows two computers to talk to each other. NetDDE, which is used with Microsoft Chat, Microsoft Hearts, and, in some cases, Excel, could cede total control to the attacker, the company warned. It's not considered a critical vulnerability because NetDDE has to be running before the attacker can take advantage of the flaw.

The vulnerability affects versions of Windows XP/NT Server 4.0 and Windows 98/98 SE/ME. Windows XP users with Service Pack 2 are not affected by the vulnerability. Users can download the patches here.

Another important security patch released Tuesday plugs a flaw found in the Remote Procedure Call (RPC) run-time library, a protocol that allows a program on one system to access services on another machine. Malware capitalizing on this flaw can either launch a DoS attack or read portions of active memory on the user's machine.

The patch, which applies to Service Pack 6 for Windows NT Server 4.0 and 4.0 Terminal Server Edition, allows the RPC Runtime Library to validate message length before it's released to the buffer. Users can download the patch here.

Users are encouraged to access Windows Update from their desktops to download and install the latest batch of patches for their computers.

News courtesy of internetnews.com

October 13, 2004


Download Internet Security Patches Now!Download

View All Microsoft Service Packs

Contents:
1. Cornucopia of Security Patches Released


Additional Articles:

  • Malware Hacker Attack Linked to Spammers
  • Malware Attack Thwarted, But Danger Lurks
  • US Gov: Beware of IE
  • Microsoft Issues Security Update for Trojan
  • Another IE Flaw in the Wild?
  • Microsoft Faces Angry IE Users' Questions
  • Microsoft Releases New Tool to Zap Download.Ject
  • Microsoft: Out-of-Cycle Security Patch Coming
  • 'Critical' IE Patch Released
  • 'Drag-and-Drop' IE Flaw Persists
  • MS Patches IFRAME Vulnerability Out of Cycle
  • Microsoft Patches Three Holes, Offers Removal Tool
  • Microsoft Patch Day Plugs 3
  • Microsoft Patches 3 Critical Flaws
  • IE Workarounds for New Zero Day Exploit
  • Unpatched IE Flaw Now Exploitable
  • Microsoft Going Critical on Tuesday
  • Microsoft Crafts Critical Patches
  • Microsoft Warns on Windows, IE Flaws
  • Microsoft Patches IE, Windows, Office
  • Microsoft's Patch of a Patch Will Be Late
  • Latest IE Zero Day Has XML Designs
  • IE Vulnerability Spreads to Email
  • IE VML Exploit Growing in Severity
  • VML Exploit Patched, Questions Remain
  • PowerPoint, IE Hit by New Zero-Day Flaws




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    IBM eBook: Planning a Service Oriented Architecture
    IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
    Intel Go Parallel Article: Getting Started with TBB on Windows
    Microsoft Article: 7.0, Microsoft's Lucky Version?
    Avaya Article: How to Feed Data into the Avaya Event Processor
    IBM Article: Developing a Software Policy for Your Organization
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    Intel Go Parallel Article: Intel Threading Tools and OpenMP
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    HP Video: StorageWorks EVA4400 and Oracle
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
    IBM Article: Enterprise Search--Do You Know What's Out There?
    HP Demo: StorageWorks EVA4400
    Microsoft Article: The Progress and Promise of Deep Zoom
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES