看板NetSecurity
标 题【TWCERT/CC安全通报】TW-CA-2005-041-[TA05-102A: Multiple Vulnerabilit
发信站KKCITY (Fri Apr 15 10:19:23 2005)
转信站ptt!ctu-reader!ctu-peer!news.nctu!netnews.csie.nctu!news.ee.ttu!news.n
※ 本文转录自 [Lan] 信箱
作者:
[email protected] (TWCERT/CC Fellows)
标题: 【TWCERT/CC安全通报】TW-CA-2005-041-[TA05-102A
时间: Thu Apr 14 10:54:00 2005
-----BEGIN PGP SIGNED MESSAGE-----
TW-CA-2005-041-[TA05-102A: Multiple Vulnerabilities in Microsoft Windows
Components Precedence: list]
────────────────────────────────────────
TWCERT/CC发布日期:2005-04-14
原漏洞发布日期:2005-04-12
原漏洞最新更新日期:--
通用安全漏洞编号:
分类:Miscellaneous
来源参考:TA05-102A
──── 简述 ─────────────────────────────────
微软在 2005 年四月时发布了一则安全性公告摘要。摘要中说明了一些 Windows 应用程
式和元件所存在的漏洞。远端攻击者可利用这些漏洞在主机上执行任意程式码。关於这
些漏洞及其影响之细节,可参考以下说明。
──── 说明 ─────────────────────────────────
以下列表提供了微软安全性公告和相关 US-CERT 弱点编号的对应,更多的详细资讯可以在
这些文件中取得。
微软安全性公告 MS05-020:
Internet Explorer 积存安全性更新 (890923)
‧VU#774338 微软的 IE DHTML 物件包含一个竞赛问题
‧VU#756122 微软的 IE URL 验证包含了一个缓冲区溢位漏洞
‧VU#222050 微软的 IE Content Advisor 包含了一个缓冲区溢位漏洞
微软安全性公告 MS05-021:
Exchange Server 中的弱点可能会允许远端执行程式码 (894549)
‧VU#774338 微软的 Exchange Server 在SMTP extended verb handling 包含未检查缓冲区
微软安全性公告 MS05-022:
MSN Messenger 中的弱点可能会允许远端执行程式码 (896597)
‧VU#633446 微软 MSN Messenger GIF processing 缓冲区溢位
微软安全性公告 MS05-019:
TCP/IP 中的弱点可能会允许远端执行程式码和拒绝服务 (893066)
‧VU#233754 微软 Windows 并未适当地验证 IP 封包
──── 影响平台 ───────────────────────────────
* 微软 Windows 系统
请参考微软安全性公告,进一步得知受影响 Windows 作业系统与元件之详细列表
──── 修正方式 ───────────────────────────────
安装更新程式
微软已於安全性公告及 Windows Update 提供数个弱点的更新档。
──── 影响结果 ───────────────────────────────
──── 联络TWCERT/CC ─────────────────────────────
Tel: 886-7-5250211 FAX: 886-7-5250212
886-2-23563303 886-2-23924082
Email:
[email protected]
URL:
http://www.cert.org.tw/
PGP key:
http://www.cert.org.tw/eng/pgp.htm
────────────────────────────────────────
附件:[ Multiple Vulnerabilities in Microsoft Windows Components Precedence:
list]
──── 原文 ─────────────────────────────────
Hash: SHA1
National Cyber Alert System
Technical Cyber Security Alert TA05-102A
Multiple Vulnerabilities in Microsoft Windows Components
Original release date: April 12, 2005
Last revised: --
Source: US-CERT
Systems Affected
* Microsoft Windows Systems
For a complete list of affected versions of the Windows operating
systems and components, refer to the Microsoft Security Bulletins.
Overview
Overview
Microsoft has released a Security Bulletin Summary for April, 2005.
This summary includes several bulletins that address
vulnerabilities in various Windows applications and
components. Exploitation of some vulnerabilities can result in the
remote execution of arbitrary code by a remote attacker. Details of
the vulnerabilities and their impacts are provided below.
I. Description
The list below provides a mapping between Microsofts Security
Bulletins and the related US-CERT Vulnerability Notes. More
information related to the vulnerabilities is available in these
documents.
Microsoft Security Bulletin MS05-020:
Cumulative Security Update for Internet Explorer (890923)
VU#774338 Microsoft Internet Explorer DHTML objects contain a
race condition
VU#756122 Microsoft Internet Explorer URL validation routine
contains a buffer overflow
VU#222050 Microsoft Internet Explorer Content Advisor contains a
buffer overflow
Microsoft Security Bulletin MS05-02:
Vulnerability in Exchange Server Could Allow Remote Code
Execution (894549)
VU#275193 Microsoft Exchange Server contains unchecked buffer in SMTP
extended verb handling
Microsoft Security Bulletin MS05-022:
Vulnerability in MSN Messenger Could Lead to Remote Code Execution
(896597)
VU#633446 Microsoft MSN Messenger GIF processing
buffer overflow
Microsoft Security Bulletin MS05-019:
Vulnerabilities in TCP/IP Could Allow Remote Code Execution and Denial
of Service (893066)
VU#233754 Microsoft Windows does not adequately validate IP
packets
II. Impact
Exploitation of these vulnerabilities may permit a remote attacker to
execute arbitrary code on a vulnerable Windows system, or cause a
denial-of-service condition.
III. Solution
Apply a patch
Microsoft has provided the patches for these vulnerabilities in the
Security Bulletins and on Windows Update.
Appendix A. References
* Microsofts Security Bulletin Summary for April, 2005 - <
http://www.microsoft.com/technet/security/bulletin/ms05-apr.mspx>
* US-CERT Vulnerability Note VU#774338 -
<
http://www.kb.cert.org/vuls/id/774338>
* US-CERT Vulnerability Note VU#756122 -
<
http://www.kb.cert.org/vuls/id/756122>
* US-CERT Vulnerability Note VU#222050 -
<
http://www.kb.cert.org/vuls/id/222050>
* US-CERT Vulnerability Note VU#275193 -
<
http://www.kb.cert.org/vuls/id/275193>
* US-CERT Vulnerability Note VU#633446 -
<
http://www.kb.cert.org/vuls/id/633446>
* US-CERT Vulnerability Note VU#233754 -
<
http://www.kb.cert.org/vuls/id/233754>
_________________________________________________________________
Feedback can be directed to the authors: Will Dormann, Jeff Gennari,
Chad Dougherty, Ken MacInnis, Jason Rafail, Art Manion, and Jeff
Havrilla.
_________________________________________________________________
This document is available from:
<
http://www.us-cert.gov/cas/techalerts/TA05-102A.html>
_________________________________________________________________
Copyright 2005 Carnegie Mellon University.
Terms of use: <
http://www.us-cert.gov/legal.html>
_________________________________________________________________
Revision History
April 12, 2005: Initial release
────────────────────────────────────────
-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.4
iQEVAwUBQl3ahKcyQYefg2/NAQG9cgf/XFSdDJmmPCC/VQw41iHvF5JC76cWUDef
/G2b6NEGdBLRzdLF4QL4lpI0snfAhMo5NaoIYSL7AGYgQlBgDO/sSg5lqUeuy2bP
+agdxnCLhGASehAJvCa2MM9Zl9IHCZbV4+1AgzfaDtj1NkzWdtCP5yvW+iYY3zjL
/OFFFyEdD2q/rUguIH8AzhzELOYd5UreWFfhZronu35r3CFeBqfDJx1pucYKUXPi
Md1I/gPzjczbBRJPMuzWsaSCRkbLeqZvPvE5lN7eFskstKc5lT1Jrfta3EscxlJh
mnFXv5eAIEX4Mssx6ABkmRbcydM6BKRPJATy4utzR+VDzvz/4vmGVA==
=yQhF
-----END PGP SIGNATURE-----
--
Taiwan Computer Emergency Response Team Security Advisory mailing list.
Mail to :
[email protected] and include a line "subscribe advisory".
Please visit
http://www.cert.org.tw/.
PGP key :
http://www.cert.org.tw/eng/pgp.htm