• Virtuozity
  • Serverity
  • Zencurity
  • projectITion

Zencurity

security by reason / less information, more knowledge - by Michael Burger
  • Home
  • Contact
  • Log in
  • Zencurity

  • XING Profil
  • Categories

    • All
    • Nicht kategorisiert
    • System
      • ESX
      • Linux
      • SQL Server
      • Windows
    • Typ
      • Alarm
        • 1 - Moderately Critical
        • 2 - Highly Critical
        • 3 - Extremely Critical
      • Howto
      • Knowledge
      • News

IE: iepeers.dll Use-After-Free Vulnerability

Permalink Mar 15, 2010 at 09:45:17 am | By michaelburger | Category: 3 - Extremely Critical | Send feedback »

A vulnerability has been discovered in Internet Explorer 6 & 7, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a use-after-free error in iepeers.dll when handling invalid values passed to the "setAttribute()" function. This can be exploited to dereference invalid memory when a specially crafted web page using the "#default#userData" behavior is accessed. Successful exploitation allows execution of arbitrary code.

You should update to IE8 or set the Internet zone security setting to "High" or disable Active Scripting support.

The vulnerability is currently being actively exploited!


Apache HTTP 2.2 Server Multiple Vulnerabilities

Permalink Mar 5, 2010 at 01:33:52 pm | By michaelburger | Category: 2 - Highly Critical | Send feedback »

Link: http://httpd.apache.org/security/vulnerabilities_22.html

Some vulnerabilities have been reported in Apache HTTP Server, which can be exploited by malicious people to gain access to potentially sensitive information, cause a DoS and potentially compromise a vulnerable system.

  1. The "ap_proxy_ajp_request()" function in modules/proxy/mod_proxy_ajp.c of the mod_proxy_ajp module returns the "HTTP_INTERNAL_SERVER_ERROR" error code when processing certain malformed requests. This can be exploited to put the backend server into an error state until the retry timeout expired by sending specially crafted requests.
  2. The mod_isapi module unloads ISAPI modules before the request processing is complete, potentially leaving orphaned callback pointers behind. This can be exploited by sending a specially crafted request followed by a reset packet. Successful exploitation may allow the execution of arbitrary code with SYSTEM privileges on Windows systems.
  3. An error exists within the header handling when processing subrequests, which can lead to sensitive information from a request being handled by the wrong thread if a multi-threaded Multi-Processing Module (MPM) is used.

Update to version 2.2.15 as soon as it becomes available.


Microsoft Data Analyzer ActiveX Control Vulnerability

Permalink Feb 12, 2010 at 10:18:52 am | By michaelburger | Category: 2 - Highly Critical | Send feedback »

Link: http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx

A vulnerability has been reported in Microsoft Data Analyzer, which can be exploited by malicious people to compromise a user's system. The vulnerability affects all Windows operating systems.

The vulnerability is caused due to an unspecified error in the Microsoft Data Analyzer ActiveX control (max3activex.dll). This can be exploited to cause a system state corruption and execute arbitrary code via a specially crafted web page.


DirectShow AVI File Parsing Buffer Overflow Vulnerability

Permalink Feb 10, 2010 at 03:43:08 pm | By michaelburger | Category: 2 - Highly Critical | Send feedback »

Link: http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx

A vulnerability has been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when parsing AVI files and can be exploited to cause a heap-based buffer overflow.

Successful exploitation allows execution of arbitrary code.


Microsoft Paint JPEG Parsing Integer Overflow Vulnerability

Permalink Feb 10, 2010 at 03:16:02 pm | By michaelburger | Category: 1 - Moderately Critical | Send feedback »

Link: http://www.microsoft.com/technet/security/Bulletin/MS10-005.mspx

Tielei Wang has discovered a vulnerability in Microsoft Windows 2000, XP and Server 2003, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an integer overflow error in Microsoft Paint when parsing certain image content. This can be exploited to cause a heap-based buffer overflow by tricking a user into viewing a specially crafted JPEG image.

Successful exploitation may allow execution of arbitrary code.


1 2 3 4 5 6 7 8 9 10 11 ... 13 >>
  • September 2010
    Sun Mon Tue Wed Thu Fri Sat
     << <   > >>
          1 2 3 4
    5 6 7 8 9 10 11
    12 13 14 15 16 17 18
    19 20 21 22 23 24 25
    26 27 28 29 30    
    • Recently
    • Archives
    • Categories
    • Latest comments
  • Search

  • XML Feeds

    • RSS 2.0: Posts, Comments
    • Atom: Posts, Comments
    What is RSS?

  • Zencurity


  • Zencurity


  • Zencurity


  • Zencurity


  • Zencurity


  • Zencurity



  • Locations of visitors to this page

contact | bae skin | blogging software | hosting