[MS] Mehrere Schwachstellen in Microsoft PowerPoint - MS10-004

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Liebe Kolleginnen und Kollegen,

soeben erreichte uns nachfolgende Warnung des Microsoft Product Security
Notification Service. Wir geben diese Informationen unveraendert an Sie
weiter.

CVE-2010-0032 / CVE-2010-0031 / CVE-2010-0030 / CVE-2010-0029 – Mehrere
Schwachstellen in Microsoft PowerPoints Dateiverarbeitung

Microsoft Office PowerPoint enthaelt mehrere
Remote-Code-Execution-Schwachstellen in der Verarbeitung von speziell
praeparierten PowerPoint-Dateien.

Im Einzelnen handelt es sich dabei um einen Buffer-Overflow bei der
Verarbeitung von Dateipfaden (CVE-2010-0029, betriff PowerPoint 2002
Service Pack 3). Es existiert ein Heap-Overflow bei der Verarbeitung
von LinkedSlideAtom-Feldern und eine Use-After-Free-Schwachstelle bei
OEPlaceholderAtom-Feldern (CVE-2010-0030, CVE-2010-0032, betrifft
PowerPoint 2002 und 2003 fuer Windows jeweils mit Service Pack 3). Des
Weiteren laesst sich eine fehlerhafte Arrayindizierung bei
OEPlaceholderAtom-placementId-Feldern ausnutzen (CVE-2010-0031,
betrifft PowerPoint 2002 und 2003 fuer Windows jeweils mit Service Pack
3 und Office 2004 fuer Mac).

Ein Angreifer kann diese Schwachstellen dazu ausnutzen, um (1)
Programme zu installieren, (2) Daten anzusehen, zu aendern oder zu
loeschen oder (3) neue Benutzerkonten mit den Rechten des angemeldeten
Benutzers zu erstellen.

CVE-2010-0033 / CVE-2010-0034 – Mehrere Schwachstellen in Microsoft
PowerPoint Viewers Dateiverarbeitung

Microsoft Office PowerPoint Viewer enthaelt mehrere
Remote-Code-Execution-Schwachstellen in der Verarbeitung von speziell
praeparierten PowerPoint-Dateien. Hierbei handelt es sich um einen
Stack-Overflow bei der Verarbeitung von TextBytesAtom (CVE-2010-0033)
und TextCharsAtom (CVE-2010-0034) Feldern.

Ein Angreifer kann diese Schwachstellen dazu ausnutzen, um (1)
Programme zu installieren, (2) Daten anzusehen, zu aendern oder zu
loeschen oder (3) neue Benutzerkonten mit den Rechten des angemeldeten
Benutzers zu erstellen.

Betroffen sind die folgenden Software Pakete und Plattformen:

Microsoft Office PowerPoint 2002 Service Pack 3 (Microsoft Office XP
Service Pack 3)
Microsoft Office PowerPoint 2003 Service Pack 3 (Microsoft Office 2003
Service Pack 3)
Microsoft Office 2004 for Mac

Microsoft Windows
Mac OS X

Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.

Hersteller Advisory:
http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx

(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.

Mit freundlichen Gruessen,
Christian Keil

– —
Dr.-Ing. Christian Keil (Senior Researcher)
DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-590
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski

17. DFN Workshop “Sicherheit in vernetzten Systemen” 09./10.02.2010
Informationen unter https://www.dfn-cert.de/veranstaltungen/workshop.html

– —–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

===========================================================================
AUSCERT External Security Bulletin Redistribution

ESB-2010.0131
Vulnerabilities in Microsoft Office PowerPoint Could Allow
Remote Code Execution
10 February 2010

===========================================================================

AusCERT Security Bulletin Summary
———————————

Product: Microsoft Office XP Service Pack 3
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
PowerPoint Viewer 2007 Service Pack 1 and PowerPoint
Viewer 2007 Service Pack 2
Microsoft Office Compatibility Pack for Word, Excel,
and PowerPoint 2007
File Formats Service Pack 1 and Microsoft Office
Compatibility Pack for Word, Excel, and PowerPoint
2007 File Formats Service Pack 2
Microsoft Works 8.5
Microsoft Works 9
Publisher: Microsoft
Operating System: Windows
Mac OS X
Impact/Access: Execute Arbitrary Code/Commands — Remote with User Interaction
Resolution: Patch/Upgrade
CVE Names: CVE-2010-0032 CVE-2010-0031 CVE-2010-0030
CVE-2010-0029

Original Bulletin:
http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx

– – ————————–BEGIN INCLUDED TEXT——————–

Microsoft Security Bulletin MS10-004 – Important

Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code
Execution (975416)

Published: February 09, 2010

Version: 1.0

General Information

Executive Summary

This security update resolves six privately reported vulnerabilities in
Microsoft Office PowerPoint. The vulnerabilities could allow remote code
execution if a user opens a specially crafted PowerPoint file. An attacker
could then install programs; view, change, or delete data; or create new
accounts with full user rights. Users whose accounts are configured to
have fewer user rights on the system could be less impacted than users who
operate with administrative user rights.

This security update is rated Important for supported editions of Microsoft
Office PowerPoint 2002 and Microsoft Office PowerPoint 2003, and Microsoft
Office 2004 for Mac.

The security update addresses the vulnerabilities by changing the way that
Microsoft Office PowerPoint and Microsoft PowerPoint Viewer parse specially
crafted PowerPoint files.

Recommendation. Microsoft recommends that customers apply the update at the
earliest opportunity.

Known Issues. Microsoft Knowledge Base Article 975416 documents the
currently known issues that customers may experience when installing this
security update. The article also documents recommended solutions for these
issues. When currently known issues and recommended solutions pertain only
to specific releases of this software, this article provides links to
further articles.

Affected Software

Microsoft Office XP Service Pack 3
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
PowerPoint Viewer 2007 Service Pack 1 and PowerPoint Viewer 2007 Service
Pack 2
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007
File Formats Service Pack 1 and Microsoft Office Compatibility Pack for
Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
Microsoft Works 8.5
Microsoft Works 9

Vulnerability Information

PowerPoint File Path Handling Buffer Overflow Vulnerability – CVE-2010-0029

A remote code execution vulnerability exists in the way that Microsoft
Office PowerPoint handles specially crafted PowerPoint files. An attacker
who successfully exploited this vulnerability could take complete control
of an affected system. An attacker could then install programs; view,
change, or delete data; or create new accounts with full user rights.

PowerPoint LinkedSlideAtom Heap Overflow Vulnerability – CVE-2010-0030

A remote code execution vulnerability exists in the way that Microsoft
Office PowerPoint handles specially crafted PowerPoint files. An
attacker who successfully exploited this vulnerability could take
complete control of an affected system. An attacker could then install
programs; view, change, or delete data; or create new accounts with
full user rights.

PowerPoint OEPlaceholderAtom ‘placementId’ Invalid Array Indexing
Vulnerability – CVE-2010-0031

A remote code execution vulnerability exists in the way that Microsoft
Office PowerPoint handles specially crafted PowerPoint files. An
attacker who successfully exploited this vulnerability could take
complete control of an affected system. An attacker could then install
programs; view, change, or delete data; or create new accounts with full
user rights.

PowerPoint OEPlaceholderAtom Use After Free Vulnerability – CVE-2010-0032

A remote code execution vulnerability exists in the way that Microsoft
Office PowerPoint handles specially crafted PowerPoint files. An
attacker who successfully exploited this vulnerability could take
complete control of an affected system. An attacker could then install
programs; view, change, or delete data; or create new accounts with
full user rights.

– – ————————–END INCLUDED TEXT——————–

You have received this e-mail bulletin as a result of your organisation’s
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT’s members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation’s
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author’s website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in
any way, we encourage you to let us know by completing the secure National IT
Incident Reporting Form at:

http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
– —–BEGIN PGP SIGNATURE—–
Comment: http://www.auscert.org.au/render.html?it=1967

iD8DBQFLcg4S/iFOrG6YcBERArXUAJ48dY2xH4+QotgS+6cQjWT62RK7yQCcCjIY
4RWYPUitJ1Xm5rRnXnOJ9VY=
=MRgi
– —–END PGP SIGNATURE—–
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFLcnofWmhIvjFb90URAgH3AKCVPD5iwRbSx3IP+mkPzq1KWjL/HACghAEL
23JYI0DHvWBF1td+/pvmQYQ=
=iilv
—–END PGP SIGNATURE—–

Nach oben