This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Trend Micro Officescan Vuln - Update Available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/25778/
Release Date: 2007-06-26
Last Update: 2007-06-27
Critical: Moderately critical
Impact: Security Bypass, System access
Where: From local network
Solution Status: Vendor Patch
Software: Trend Micro OfficeScan Corporate Edition 8.x
…The vulnerabilities affect OfficeScan Corporate Edition version 8.0.
Solution: Apply Security Patch - Build 1042:
http://www.trendmicro.com/ftp/products/pat…patch_b1042.exe
Original Advisory:
http://preview.tinyurl.com/2reorc …"


:ph34r:
Updated:

- http://secunia.com/advisories/25778
…The vulnerabilities affect OfficeScan Corporate Edition versions 8.0, 7.0, and 7.3.
Solution: Apply patches.
OfficeScan 8.0:
http://www.trendmicro.com/ftp/products/pat…patch_b1042.exe
OfficeScan 7.0:
http://www.trendmicro.com/ftp/products/pat…patch_b1364.exe
OfficeScan 7.3:
http://www.trendmicro.com/ftp/products/pat…patch_b1293.exe
Provided and/or discovered by: Reported by the vendor.
Changelog:
2007-06-27: Added CVE reference. Added additional affected product version.
2007-06-28: Updated vendor link.
2007-06-29: Added additional affected product version.
Original Advisory:
http://www.trendmicro.com/ftp/documentatio…1042_readme.txt
http://www.trendmicro.com/ftp/documentatio…1364_readme.txt
http://www.trendmicro.com/ftp/documentatio…1293_readme.txt

:ph34r:
FYI…

- http://atlas.arbor.net/briefs/index#-1118575019
July 17, 2007 - "A malicious web request with an overly long session cookie can be sent to the Trend Micro OfficeScan web interface to trigger a buffer overflow in the component CGIOCommon.dll. Successful exploitation can allow the remote, anonymous attacker to execute code on the system with the permissions of the IIS web server. Trend Micro has released updated code to address this issue.
Analysis: This is a relatively trivial attack to launch for most attackers. We have not yet seen tools to exploit this, but we expect that some will be developed soon.
Source:
> http://labs.idefense.com/intelligence/vuln…play.php?id=559
7.16.07 - "…Trend Micro has addressed this vulnerability by releasing the following patches for affected products.
CSM3.6 security patch 1149
CSM3.5 security patch 1152
CSM3.0 security patch 1209
http://www.trendmicro.com/download/product.asp?productid=39
OSCE 8.0 security patch 1042
OSCE 7.3 security patch 1293
OSCE 7.0 security patch 1364
OSCE 6.5 security patch 1364
OSCE 6.0 for SMB2.0 security patch 1398
http://www.trendmicro.com/download/product.asp?productid=5 …"

.