Weekly Vulnerabilities Reports > November 1 to 7, 2004

Overview

34 new vulnerabilities reported during this period, including 8 critical vulnerabilities and 10 high severity vulnerabilities. This weekly summary report vulnerabilities in 31 products from 15 vendors including Microsoft, Debian, Oracle, PHP, and Mysql. Vulnerabilities are notably categorized as "Out-of-bounds Write", "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Path Traversal", "Improper Input Validation", and "Divide By Zero".

  • 29 reported vulnerabilities are remotely exploitables.
  • 1 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 34 reported vulnerabilities are exploitable by an anonymous user.
  • Microsoft has the most reported vulnerabilities, with 18 reported vulnerabilities.
  • Microsoft has the most reported critical vulnerabilities, with 7 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

8 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-11-03 CVE-2004-0840 Microsoft Improper Input Validation vulnerability in Microsoft Exchange Server, Windows Server 2003 and Windows XP

The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.

10.0
2004-11-03 CVE-2004-0836 Oracle
Debian
Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products

Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).

10.0
2004-11-03 CVE-2004-0575 Microsoft Unspecified vulnerability in Microsoft Windows 2003 Server and Windows XP

Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.

10.0
2004-11-03 CVE-2004-0574 Microsoft Out-Of-Bounds Write vulnerability in Microsoft products

The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.

10.0
2004-11-03 CVE-2004-0572 Microsoft Local Buffer Overrun vulnerability in Microsoft Windows Program Group Converter Filename

Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.

10.0
2004-11-03 CVE-2004-0216 Microsoft Unspecified vulnerability in Microsoft IE 5.01/5.5/6

Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.

10.0
2004-11-03 CVE-2004-0214 Microsoft Buffer Overrun vulnerability in Microsoft Windows Shell Long Share Name

Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.

10.0
2004-11-03 CVE-2004-0209 Microsoft Remote Buffer Overflow vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP

Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

10.0

10 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-11-03 CVE-2004-0774 Realnetworks Unspecified vulnerability in Realnetworks products

RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.

7.8
2004-11-03 CVE-2004-0885 Apache Unspecified vulnerability in Apache Http Server

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

7.5
2004-11-03 CVE-2004-0847 Microsoft Path Traversal vulnerability in Microsoft Asp.Net 1.0/1.1

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

7.5
2004-11-03 CVE-2004-0846 Microsoft Unspecified vulnerability in Microsoft Excel and Office

Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.

7.5
2004-11-03 CVE-2004-0835 Mysql
Oracle
Debian
Local vulnerability in MySQL

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

7.5
2004-11-03 CVE-2004-0815 Samba Remote Arbitrary File Access vulnerability in Samba

The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.

7.5
2004-11-03 CVE-2004-0569 Microsoft Unspecified vulnerability in Microsoft Windows NT 4.0

The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.

7.5
2004-11-03 CVE-2004-0552 Sophos Unspecified vulnerability in Sophos Small Business Suite

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

7.5
2004-11-03 CVE-2004-0206 Microsoft Remote Buffer Overflow vulnerability in Microsoft Windows NetDDE

Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.

7.5
2004-11-03 CVE-2004-0208 Microsoft Unspecified vulnerability in Microsoft products

The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.

7.2

11 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-11-03 CVE-2004-0845 Microsoft Unspecified vulnerability in Microsoft IE 5.01/5.5/6

Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.

6.4
2004-11-03 CVE-2004-0958 PHP Unspecified vulnerability in PHP

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

5.0
2004-11-03 CVE-2004-0938 Freeradius Attribute Decoding Denial Of Service vulnerability in FreeRADIUS

FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.

5.0
2004-11-03 CVE-2004-0920 Symantec Unspecified vulnerability in Symantec Norton Antivirus

Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.

5.0
2004-11-03 CVE-2004-0911 Debian Unspecified vulnerability in Debian Netkit 0.07/0.17

telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.

5.0
2004-11-03 CVE-2004-0844 Microsoft Unspecified vulnerability in Microsoft IE 6

Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."

5.0
2004-11-03 CVE-2004-0843 Microsoft Unspecified vulnerability in Microsoft IE 5.5/6

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

5.0
2004-11-03 CVE-2004-0832 Squid Denial Of Service vulnerability in Squid Proxy NTLM Authentication

The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.

5.0
2004-11-03 CVE-2003-0718 Microsoft Unspecified vulnerability in Microsoft products

The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.

5.0
2004-11-01 CVE-2004-1121 Apple Unspecified vulnerability in Apple Safari

Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.

5.0
2004-11-03 CVE-2004-0804 Libtiff Divide BY Zero vulnerability in Libtiff

Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.

4.3

5 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2004-11-03 CVE-2004-0837 Mysql
Oracle
Debian
Local vulnerability in MySQL

MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.

2.6
2004-11-03 CVE-2004-0959 PHP Unspecified vulnerability in PHP

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

2.1
2004-11-03 CVE-2004-0828 IBM Local File Corruption vulnerability in IBM CTSTRTCASD Utility

The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.

2.1
2004-11-03 CVE-2004-0211 Microsoft Unspecified vulnerability in Microsoft Windows 2003 Server R2

The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

2.1
2004-11-03 CVE-2004-0207 Microsoft Unspecified vulnerability in Microsoft products

"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.

2.1