Video | Business Headlines | Internet | Science | Scientific Ethics | Technology | Search

 


Microsoft security update - Mon, 2 Aug 2004

Symantec Security Response: Microsoft security update

Mon, 2 Aug 2004

On Friday (US time), Microsoft announced a cumulative security update for Microsoft Internet Explorer impacting both consumer and enterprise users. The update is replacing a recent cumulative update provided in Microsoft Security Bulletin MS04-004. (http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx)

This Microsoft update resolves several newly discovered product vulnerabilities - all of these vulnerabilities are rated critical. If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs such as spyware and backdoors, viewing, changing, or deleting data, and creating new accounts with full privileges.

"With the widespread use of Microsoft Internet Explorer in both the enterprise and consumer environments, it is critical that security patches be applied immediately", said Alfred Huger, senior director, Symantec Security Response. "Symantec has already seen exploits in the wild taking advantage of at least one of these vulnerabilities."

Symantec Security Response is monitoring these vulnerabilities through its Managed Security Services as well as through its DeepSight Early Warning Solutions. Symantec Security Response will also be monitoring for any potential new exploits leveraging these vulnerabilities.

Please see below for detailed summaries of these updates. If you'd like to speak with a Symantec security expert regarding any of these vulnerabilities, please contact Rachael Joel on 09 303 3862, 021 403 504 or rachaelj@botica.co.nz.

1. Navigation Method Cross-Domain Vulnerability (CAN-2004-0549) Overview/Risk: At this time, Symantec Security Response views this vulnerability as the most critical. Symantec has already seen exploits in the wild that leverage this vulnerability.

A remote code execution vulnerability exists in Internet Explorer because of the way it handles navigation methods.

An attacker could exploit the vulnerability by constructing a malicious web page that could potentially allow remote code execution if a user visited a malicious Web site. If a user is logged on with administrative privileges, this could allow the attacker to take complete control of an affected system.

However, in a Web-based attack, the attacker would have to persuade the user to visit a malicious Web site, typically by getting them to clink on a link. Also, users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.

Systems impacted include Internet Explorer 5.5 SP2, Internet Explorer 6, Internet Explorer 6 SP1 (All versions earlier than Windows Server 2003), and Internet Explorer 6 for Windows Server 2003 (including 64-bit Edition).

Symantec Security Response has rated this threat at a High risk.

2. Malformed BMP File Buffer Overrun Vulnerability (CAN-2004-0556) Overview/Risk: A buffer overrun vulnerability exists in the processing of BMP image file formats that could allow remote code execution on an affected system.

In a Web-based attack, the attacker would have to persuade the user to visit a malicious Web site, typically by getting them to click on a link. Also, users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.

Systems impacted include Internet Explorer 5.01 SP2, SP3 and SP4, Internet Explorer 5.5 SP2, Internet Explorer 6.

Symantec Security Response has rated this threat at a High risk.

3. Malformed GIF File Double Free Vulnerability (CAN-2003-1048) Overview/Risk: A buffer overrun vulnerability exists in the processing of GIF image file formats that could allow remote code execution on an affected system.

In a Web-based attack, the attacker would have to persuade the user to visit a malicious Web site, typically by getting them to clink on a link. Also, users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.

Systems impacted include Internet Explorer 5.01 SP2, SP3 and SP4, Internet Explorer 5.5 SP2, Internet Explorer 6, Internet Explorer 6 SP1 (All versions earlier than Windows Server 2003), and Internet Explorer 6 for Windows Server 2003 (including 64-bit Edition).

Symantec Security Response rates this threat as a High risk.

ENDS

© Scoop Media

 
 
 
 
 
Business Headlines | Sci-Tech Headlines

 

Sky City : Auckland Convention Centre Cost Jumps By A Fifth

SkyCity Entertainment Group, the casino and hotel operator, is in talks with the government on how to fund the increased cost of as much as $130 million to build an international convention centre in downtown Auckland, with further gambling concessions ruled out. The Auckland-based company has increased its estimate to build the centre to between $470 million and $530 million as the construction boom across the country drives up building costs and design changes add to the bill.
More>>

ALSO:

RMTU: Mediation Between Lyttelton Port And Union Fails

The Rail and Maritime Union (RMTU) has opted to continue its overtime ban indefinitely after mediation with the Lyttelton Port of Christchurch (LPC) failed to progress collective bargaining. More>>

Earlier:

Science Policy: Callaghan, NSC Funding Knocked In Submissions

Callaghan Innovation, which was last year allocated a budget of $566 million over four years to dish out research and development grants, and the National Science Challenges attracted criticism in submissions on the government’s draft national statement of science investment, with science funding largely seen as too fragmented. More>>

ALSO:

Scoop Business: Spark, Voda And Telstra To Lay New Trans-Tasman Cable

Spark New Zealand and Vodafone, New Zealand’s two dominant telecommunications providers, in partnership with Australian provider Telstra, will spend US$70 million building a trans-Tasman submarine cable to bolster broadband traffic between the neighbouring countries and the rest of the world. More>>

ALSO:

More:

Statistics: Current Account Deficit Widens

New Zealand's annual current account deficit was $6.1 billion (2.6 percent of GDP) for the year ended September 2014. This compares with a deficit of $5.8 billion (2.5 percent of GDP) for the year ended June 2014. More>>

ALSO:

Still In The Red: NZ Govt Shunts Out Surplus To 2016

The New Zealand government has pushed out its targeted return to surplus for a year as falling dairy prices and a low inflation environment has kept a lid on its rising tax take, but is still dangling a possible tax cut in 2017, the next election year and promising to try and achieve the surplus pledge on which it campaigned for election in September. More>>

ALSO:

Job Insecurity: Time For Jobs That Count In The Meat Industry

“Meat Workers face it all”, says Graham Cooke, Meat Workers Union National Secretary. “Seasonal work, dangerous jobs, casual and zero hours contracts, and increasing pressure on workers to join non-union individual agreements. More>>

ALSO:

Get More From Scoop

 
 
Standards New Zealand

Standards New Zealand
 
 
 
 
 
 
 
 
Sci-Tech
Search Scoop  
 
 
Powered by Vodafone
NZ independent news