TW-CA-2005-072-[RHSA-2005:504-00:Moderate: telnet security update]
==========================================================================
TWCERT發布日期: 2005-06-17
原漏洞發布日期: 2005-06-14
分類: Info Leak
來源參考: RHSA-2005:504-00
通用安全弱點編號: CAN-2005-0488
========= 簡述 ===================================================
更新 telnet 套件,修正一個資訊洩漏弱點。 Red Hat Security Response Team 將此列為中等的安全更新。
========= 說明 ====================================================
微軟在2005年6月之安全性公告已發佈了一些關於Windows, Internet Explorer, Outlook
Express,Outlook Web Access,ISA Server, the Step-by-Step Interactive Training
engine, and telnet的漏洞。詳細漏洞資訊請參閱以下弱點編號:

VU#189754 - 微軟IE 處裡PNG影像元件的緩衝區溢位漏洞
微軟IE 於處裡PNG影像元件的緩衝區溢位會使遠端攻擊者在有漏洞的系統上執行程式碼。
(CAN-2005-1211)

VU#489397 - 微軟的 Server Message Block 易有緩衝區溢位
微軟 Server Message Block (SMB) 在處裡進入SMB的封包時容易有緩衝區的缺點,這會
導致遠端攻擊者執行程式碼。(CAN-2005-1206)

VU#851869 - 微軟 HTML Help 輸入驗證錯誤
微軟 HTML Help 不能適當地驗證輸入資料,而導致遠端攻擊者執行任意程式碼。(CAN-
2005-1208)。

========= 影響平台 ====================================================
* 微軟視窗系統
* 微軟 IE 瀏覽器

更多完整的資訊,請看 2005 年6月微軟安全佈告摘要。

========= 修正方式 ====================================================
下載更新程式

微軟已經對這些漏洞於安全佈告和Windows自動更新程式提供了修補程式

相關方法

請看各別弱點編號資訊

附錄 A

* Microsoft Security Bulletin Summary for June, 2005 -
<http://www.microsoft.com/technet/security/bulletin/ms05-jun.mspx>

* US-CERT Vulnerability Note VU#189754 -
<http://www.kb.cert.org/vuls/id/189754>

* US-CERT Vulnerability Note VU#489397 -
<http://www.kb.cert.org/vuls/id/489397>

* US-CERT Vulnerability Note VU#851869 -
<http://www.kb.cert.org/vuls/id/851869>

* CAN-2005-1211 -
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1222>

* CAN-2005-1206 -
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1206>

* CAN-2005-1208 -
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1208>

* Microsoft Windows Update - <http://windowsupdate.microsoft.com/>

附件:
=================== 原文 ===========================================
Hash: SHA1

Technical Cyber Security Alert TA05-165A
Microsoft Windows and Internet Explorer Vulnerabilities

Original release date: June 14, 2005
Last revised: --
Source: US-CERT

Systems Affected

* Microsoft Windows
* Microsoft Internet Explorer

For more complete information, refer to the Microsoft Security
Bulletin Summary for June, 2005.

Overview

Microsoft has released updates that address critical vulnerabilities
in Windows and Internet Explorer. Exploitation of these
vulnerabilities could allow a remote, unauthenticated attacker to
execute arbitrary code or cause a denial of service.

I. Description

Microsoft Security Bulletins for June, 2005 address a number of
vulnerabilities in Windows, Internet Explorer, Outlook Express,
Outlook Web Access, ISA Server, the Step-by-Step Interactive Training
engine, and telnet. Further information about the more serious
vulnerabilities is available in the following Vulnerability Notes:

VU#189754 - Microsoft Internet Explorer buffer overflow in PNG image
rendering component

A buffer overflow in the PNG image rendering component of Microsoft
Internet Explorer may allow a remote attacker to execute code on a
vulnerable system.
(CAN-2005-1211)

VU#489397 - Microsoft Server Message Block vulnerable to buffer
overflow

Microsoft Server Message Block (SMB) is vulnerable to a buffer
handling flaw when processing incoming SMB packets that may lead to
remote code execution.
(CAN-2005-1206)

VU#851869 - Microsoft HTML Help input validation error

Microsoft HTML Help fails to properly validate input data, allowing a
remote attacker to execute arbitrary code.
(CAN-2005-1208)

II. Impact

Exploitation of the most serious of these vulnerabilities could allow
a remote, unauthenticated attacker to execute arbitrary code with
SYSTEM privileges. This would allow an attacker to take complete
control of a vulnerable system. An attacker could also execute
arbitrary code with user privileges, or cause a denial of service.

III. Solution

Apply updates

Microsoft has provided the patches for these vulnerabilities in the
Security Bulletins and on Windows Update.

Workarounds

Please see the individual vulnerability notes for workarounds.

Appendix A. References

* Microsoft Security Bulletin Summary for June, 2005 -
<http://www.microsoft.com/technet/security/bulletin/ms05-jun.mspx>

* US-CERT Vulnerability Note VU#189754 -
<http://www.kb.cert.org/vuls/id/189754>

* US-CERT Vulnerability Note VU#489397 -
<http://www.kb.cert.org/vuls/id/489397>

* US-CERT Vulnerability Note VU#851869 -
<http://www.kb.cert.org/vuls/id/851869>

* CAN-2005-1211 -
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1222>

* CAN-2005-1206 -
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1206>

* CAN-2005-1208 -
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1208>

* Microsoft Windows Update - <http://windowsupdate.microsoft.com/>
_________________________________________________________________

Feedback can be directed to the US-CERT Technical Staff
_________________________________________________________________

Revision History

June 14, 2005: Initial release
_________________________________________________________________

This document is available from:

<http://www.us-cert.gov/cas/techalerts/TA05-165A.html>

Produced 2005 by US-CERT, a government organization.

Terms of use

<http://www.us-cert.gov/legal.html>

For instructions on subscribing to or unsubscribing from this
mailing list, visit <http://www.us-cert.gov/cas/signup.html>.


  Top to page
安全新聞 | 詮安徵才 | 網站地圖
302 新竹縣竹北市新泰路92號8樓之1
TEL:(03)553-1836 | FAX:(03)553-5887
(C)2005 AllNetSecure Information Co., Ltd. All Rights Reserved