| Seasons Greetings from the Security Alert Consensus Team! We wish to
| extend our sincerest wishes for a very happy holiday season to all
| of you and your families.
| This week produced a few notable vulnerabilities. Admins of the
| various commercial Unixes (Solaris, HP-UX and so on) should look at
| the SystemV-derived login buffer overflow (reported as {01.51.009}
| under the Cross-Platform category). Linux users may want to update
| their glibc libraries to prevent possible overflows in the glob()
| function (reported as {01.51.024} in the Linux category). And, finally,
| so Windows users don't feel left out, Microsoft Corp. released an
| Internet Explorer mega-patch (reported as {01.51.010} in the Windows
| category). This patch fixes all nasty problems to date, including the
| one that automatically downloads and executes applications without
| warning the user.
| Special note: Microsoft today issued a critical recommendation
| regarding Windows, Windows XP, or ME machines that share internet
| connections with Windows 98/98SE clients. You can read more on and
| download this significant patch here:
| http://www.microsoft.com/technet/treeview/default.asp?url=
| /technet/security/bulletin/ms01-059.asp
| Until next time,
| --Security Alert Consensus Team
| {01.51.001} Win - IIS large, content-length header DoS
| {01.51.004} Win - IKE UDP flood DoS
| {01.51.010} Win - MS01-058: Cumulative IE patch
| {01.51.018} Win - Citrix auto-launch of .ICA files
| {01.51.025} Win - EFTP directory listing vulnerability
| {01.51.026} Win - CentraOne log file info disclosure
| - --- Windows News -------------------------------------------------------
| *** {01.51.001} Win - IIS large, content-length header DoS
| Various people are reporting a potential denial of service found in
| IIS 5.0 (and possibly other versions), whereby a remote attacker sends
| a content-length header with an extremely large value. As a result,
| the server waits for the indicated amount of data to be sent, with
| no apparent timeouts.
| This vulnerability has not been confirmed. An exploit has been
| published.
| Source: SecurityFocus Bugtraq
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0098.html
| *** {01.51.004} Win - IKE UDP flood DoS
| Various discussions in the past week have touched on the possibility
| of a denial of service attack against the IKE IPSEC service listening
| on UDP port 500. An ongoing flood can result in abnormally high CPU
| use while the packets are processed.
| This vulnerability has not been confirmed.
| Source: SecurityFocus Bugtraq
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0108.html
| *** {01.51.010} Win - MS01-058: Cumulative IE patch
| Microsoft has released MS01-058 ("Cumulative IE patch"). This patch
| fixes all known security problems in Internet Explorer to date,
| including three new problems: the ability for a malicious Web site
| to execute arbitrary applications in IE 6; the ability to read files
| from the user's system; and a bug that could allow a Web site to
| trick the user into seeing a different file name in the download box.
| FAQ and patch:
| http://www.microsoft.com/technet/security/bulletin/MS01-058.asp
| Source: Microsoft
| http://archives.neohapsis.com/archives/vendor/2001-q4/0053.html
| *** {01.51.018} Win - Citrix auto-launch of .ICA files
| An advisory was released indicating that IE will automatically
| download and launch any .ICA file presented by a malicious Web site
| or e-mail. The .ICA file could cause a connection to a trojaned
| server, thereby allowing the server to copy files from or to the
| client's machine. Apparently, only the Windows version of the client
| is affected.
| The advisory indicates vendor confirmation. A list of workarounds is
| available at:
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0133.html
| Source: SecurityFocus Bugtraq
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0133.html
| *** {01.51.025} Win - EFTP directory listing vulnerability
| EFTP version contains a bug that allows a remote attacker to
| gain directory listings outside the FTP root by sending a particular
| pattern of CWD commands.
| This vulnerability has not been confirmed.
| Source: SecurityFocus Bugtraq
| http://archives.neohapsis.com/archives/bugtraq/2001-12/0134.html
| *** {01.51.026} Win - CentraOne log file info disclosure
| The CentraOne collaboration and learning application has been found
| to create world-readable logs that contain large amounts of sensitive
| user information, including user name and password.
| This vulnerability has not been confirmed.
| Source: VulnWatch
| http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0072.html
