Home > Security News > Security Bytes: ISS warns of new Microsoft Windows flaw
Security News:
EMAIL THIS

Security Bytes: ISS warns of new Microsoft Windows flaw

By SearchSecurity.com Staff
31 Jul 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

ISS warns of new Microsoft Windows flaw
Multiple versions of Microsoft Windows are vulnerable to a NULL pointer dereference error in the server driver, which attackers could exploit to crash a system using a specially crafted network packet. Atlanta-based vendor Internet Security Systems' (ISS) X-Force uncovered the glitch and released details Friday in an advisory, warning that an exploit is available in the wild.

"Attackers can reliably cause Microsoft Windows to [go to a] blue screen," ISS said. "Users must reboot to recover from the crash … As of this writing no patch is available for the vulnerability."

ISS said the security hole affects:

  • Microsoft Windows 2000 SP4
  • Microsoft Windows Server 2003
  • Microsoft Windows Server 2003 Itanium
  • Microsoft Windows Server 2003 SP1
  • Microsoft Windows Server 2003 SP1 Itanium
  • Microsoft Windows Server 2003 x64 Edition
  • Microsoft Windows XP Pro x64 Edition
  • Microsoft Windows XP SP1
  • Microsoft Windows XP SP2

    Symantec fixes Brightmail AntiSpam flaw
    Cupertino, Calif.-based antivirus giant Symantec Corp. has fixed multiple flaws in its Brightmail AntiSpam product. Attackers could exploit the flaws to read or modify confidential system information, Symantec said in an advisory.

    "Symantec Brightmail AntiSpam fails to fully sanitize file names passed to the DATABLOB-GET / DATABLOB-SAVE requests of directory traversal sequences," Symantec said. "This directory traversal vulnerability could result in confidential system information being exposed."

    During the installation of email scanners, Symantec said three options are given for identifying the Brightmail AntiSpam control center that will control the scanner. The first option is a local control center. The second option is to identify the control center by its IP address, and the third option allows the control center to connect from any computer.

    Symantec said the third option could allow an attacker to impersonate the control center, exposing the following vulnerabilities:

  • The Brightmail AntiSpam service can be hung by sending invalid posts, causing a denial of service.
  • By combining with the directory traversal vulnerability, some system files can be read.
  • By combining with the directory traversal vulnerability, it is possible to overwrite existing files on the same drive as Symantec Brightmail AntiSpam.

    The solution is to upgrade to Symantec Brightmail AntiSpam version 6.0.4 or to Symantec Mail Security (SMS) for SMTP version 5.0.

    Tags: Security Patch ManagementEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Patch Management
    Squad: Tokenization, Phishing and the Feds
    Should management processes change based on a patch release schedule?
    Should Windows Mobile updates come from Microsoft?
    Adobe updates ColdFusion, JRun, Flex
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching
    Microsoft to issue security report card, new tool at Black Hat
    How to manage patches for Adobe
    When is it suitable to remove Java updates?

    Email and Messaging Threats (spam, phishing, instant messaging)
    Messaging security risks have upper hand on solutions
    Web-based attacks skyrocket, pirating sites surge, security firms say
    Pushdo botnet uses Facebook to spread malicious email attachment
    Scareware report highlights successful business model
    How to prevent phishing attacks with social engineering tests
    Phishing protection begins with training, antiphishing evangelist
    Phishing attacks to remain a major problem, say security experts
    Barracuda acquires Purewire expanding Web security reach
    FBI raids phishing crime ring, nearly 100 arrested
    Massive phishing scheme affects Microsoft Hotmail accounts
    Email and Messaging Threats (spam, phishing, instant messaging) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    attack vector  (SearchSecurity.com)
    back door  (SearchSecurity.com)
    ethical worm  (SearchSecurity.com)
    Patch Tuesday  (SearchSecurity.com)
    zero-day exploit  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts