Vissza a www.andrews.hu-ra

    [guru] IBM biztonsagi frissitesek


    DATE: Thu, 10 Sep 2009 22:24:16 +0200
    Az Autonomy KeyView SDK excel állományok feldolgozásakor heap buffer overflow
    hibát tartalmaz. Ez egy külső rutinkönyvtár, amit a Lotus Notes és a Symantec
    is használ a termékeiben.
    
    A Lotus Notes által használt RSS megjelenítő widget az IE-t használja a
    tényleges megjelenítésre, azonban ez a forrástól függetlenül mindíg a
    sajátgép zónában történik.
    
    
    --- Begin Message ---
    iDefense Security Advisory 08.25.09
    http://labs.idefense.com/intelligence/vulnerabilities/
    Aug 25, 2009
    
    I. BACKGROUND
    
    Autonomy KeyView SDK is a commercial SDK that provides many file format
    parsing libraries. It supports a large number of different document
    formats, one of which is the Microsoft Excel 97 (XLS) format. It is
    used by several popular vendors for processing documents. For more
    information, visit the URL referenced below.
    
    http://www.autonomy.com/
    
    KeyView is used by many commercial products to handle various types of
    file formats. Lotus Notes and Symantec Mail Security are two examples
    of such products.
    
    II. DESCRIPTION
    
    Remote exploitation of an integer overflow vulnerability in Autonomy's
    KeyView SDK allows attackers to execute arbitrary code with the
    privileges of the targeted application.
    
    The vulnerability occurs when parsing a Shared String Table (SST) record
    inside of an Excel file. This record is used to hold a table of strings
    that are used inside of the document. One of the fields in this record
    is a 32-bit integer that represents the number of strings in the table.
    This value is used in a calculation that controls the number of bytes to
    allocate for a dynamic heap buffer. The value is not properly sanitized,
    which leads to an integer overflow in the calculation. This results in a
    heap based buffer overflow vulnerability.
    
    III. ANALYSIS
    
    Exploitation allows attackers to execute arbitrary code with the
    privileges of the targeted application. In order to exploit this
    vulnerability, an attacker must cause a specially crafted Microsoft
    Excel Spreadsheet to be processed by an application using the Autonomy
    KeyView SDK.
    
    When targeting applications like Lotus Notes, this requires that an
    attacker convince a user to view an e-mail attachment; however, in
    other cases, processing may take place automatically as a document is
    examined. The specific circumstances will depend on the application
    being targeted.
    
    The privileges that an attacker gains may be different for each
    application that uses the KeyView SDK. For example, exploiting this
    issue via Lotus Notes yields the current user's privileges while
    exploiting the vulnerability via Symantec Mail Security yields SYSTEM
    privileges.
    
    IV. DETECTION
    
    iDefense confirmed the existence of this vulnerability using the
    following versions of the affected software:
    
      xlssr.dll version 8.0.0.7214, distributed with IBM Lotus Notes 8.0
      xlssr.dll version 8.5.0.8339, distributed with IBM Lotus Notes 8.5
      xlssr.dll version 10.5.0.0, distributed with Symantec Mail Security
    for Microsoft Exchange
    
    All versions of the KeyView SDK that include the "xlssr.dll" filter
    module are suspected to be vulnerable.
    
    V. WORKAROUND
    
    For all products using the KeyView SDK, you can disable the "xlssr.dll"
    filter by doing one of the following:
    
      Removing the xlssr.dll filter module from the affected system(s).
      Delete or comment out the line referencing "xlssr.dll" from the
    "KeyView.ini" file distributed with the affected application.
    
    Additionally, for Symantec Mail Security, disabling "content filtering"
    will prevent exploitation.
    
    VI. VENDOR RESPONSE
    
    IBM has released a patch which addresses this issue in Lotus Notes. For
    more information, consult their advisory at the following URL:
    
    http://www-01.ibm.com/support/docview.wss?rs=463&uid=swg21396492
    
    Symantec has released a patch which addresses this issue in several
    Symantec products. For more information, consult their advisory at the
    following URL:
    
    http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090825_00
    
    VII. CVE INFORMATION
    
    A Mitre Corp. Common Vulnerabilities and Exposures (CVE) number has not
    been assigned yet.
    
    VIII. DISCLOSURE TIMELINE
    
    05/05/2009  - Initial Contact
    05/05/2009  - Autonomy first response
    05/05/2009  - Symantec first response
    05/05/2009  - IBM first response
    05/05/2009  - Autonomy POC request
    05/05/2009  - IBM POC request
    05/06/2009  - Autonomy clarification request
    05/06/2009  - Symantec clarification request
    05/06/2009  - Request public key from Autonomy
    05/06/2009  - Sent POC to IBM, Symantec
    05/06/2009  - Symantec requests resend
    05/06/2009  - Resent POC to Symantec
    05/06/2009  - Autonomy sends public key
    05/06/2009  - Sent POC to Autonomy
    05/07/2009  - Symantec holding on Autonomy fix
    05/07/2009  - Autonomy requested clarification
    05/07/2009  - Sent clarification.
    08/11/2009  - Disclosure coordination
    08/17/2009  - Disclosure re-coordination
    08/25/2009  - Coordinated Public Disclosure
    
    IX. CREDIT
    
    This vulnerability was discovered by Joshua J. Drake of iDefense Labs.
    
    Get paid for vulnerability research
    http://labs.idefense.com/methodology/vulnerability/vcp.php
    
    Free tools, research and upcoming events
    http://labs.idefense.com/
    
    X. LEGAL NOTICES
    
    Copyright © 2009 iDefense, Inc.
    
    Permission is granted for the redistribution of this alert
    electronically. It may not be edited in any way without the express
    written consent of iDefense. If you wish to reprint the whole or any
    part of this alert in any other medium other than electronically,
    please e-mail customerservice@idefense.com for permission.
    
    Disclaimer: The information in the advisory is believed to be accurate
    at the time of publishing based on currently available information. Use
    of the information constitutes acceptance for use in an AS IS condition.
     There are no warranties with regard to this information. Neither the
    author nor the publisher accepts any liability for any direct,
    indirect, or consequential loss or damage arising from use of, or
    reliance on, this information.
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    IBM Lotus Notes 8.5 RSS Widget Privilege Escalation
    
    scip AG Vulnerability ID 4021 (09/08/2009)
    http://www.scip.ch/?vuldb.4021
    
    I. INTRODUCTION
    
    Lotus Notes is a client-server, collaborative application developed and
    sold by IBM Software Group.
    
    More information is available on the official product web site at the
    following URL:
    
    http://www.ibm.com/software/lotus/products/notes/
    
    II. DESCRIPTION
    
    Marc Ruef at scip AG found a design vulnerability in the current Release
    8.5.
    
    The product provides some widgets which can be added and enabled by the
    user. One of those widgets provide a simple RSS reader.
    
    This reader downloads the RSS file, extracts the items and saves them
    locally as HTML files.
    
    The interpretation and display of the RSS items is handled by the
    Internet Explorer regarding the applied security zone.
    
    III. EXPLOITATION
    
    No exploitation is required. A malicious RSS feed may contain script
    data or embedded objects.
    
    IV. IMPACT
    
    The RSS items are handled like web documents which introduces the
    possibility of running script code or to embed multimedia objects (e.g.
    Flash or movies).
    
    Because locally saved files run in the Local Zone of the Internet
    Explorer some privilege escalation is possible.
    
    V. DETECTION
    
    It may be possible to identify malicious RSS feeds if they contain
    script code or embedded objects.
    
    VI. SOLUTION
    
    IBM has been informed immediately. They are able to address this
    vulnerability with a hotfix.
    
    VII. VENDOR RESPONSE
    
    The vendor verified the existence of the issue and addressed it as soon
    as possible with a hotfix. Unfortunately most of the communication
    bypassed us and were forced to ask for the current status several times.
    Our last request of the current status at 08/24/2009 were unanswered.
    
    VIII. SOURCES
    
    scip AG - Security Consulting Information Process (german)
    http://www.scip.ch/
    
    scip AG - Vulnerability Database (german)
    http://www.scip.ch/?vuldb.4021
    
    computec.ch Document Database (german)
    http://www.computec.ch/download.php
    
    IX. DISCLOSURE TIMELINE
    
    2009/04/07 Identification of the vulnerability.
    2009/04/23 Notification of IBM via the customer.
    2009/04/23 Technical knowhow exchange between scip AG/IBM.
    2009/06/05 Asking for current status by scip AG. (no answer)
    2009/07/09 Asking for current status by scip AG.
    2009/07/09 Reply with current status and assigned PMR.
    2009/08/24 Asking for current status by scip AG. (no answer)
    2009/09/08 Public disclosure of the advisory.
    
    X. CREDITS
    
    The vulnerabilities were discovered by Marc Ruef.
    
    Marc Ruef, scip AG, Zuerich, Switzerland
    maru-at-scip.ch
    http://www.scip.ch
    
    A1. LEGAL NOTICES
    
    Copyright (c) 2002-2009 scip AG, Switzerland.
    
    Permission is granted for the re-distribution of this alert. It may not
    be edited in any way without permission of scip AG.
    
    The information in the advisory is believed to be accurate at the time
    of publishing based on currently available information. There are no
    warranties with regard to this information. Neither the author nor the
    publisher accepts any liability for any direct, indirect or
    consequential loss or damage from use of or reliance on this advisory.
    
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra