AplusWebMaster
Topic Starter
FYI…
> http://isc.sans.org/diary.html?storyid=3929
Last Updated: 2008-02-04 19:52:11 UTC (References Symantec info below)
- http://www.symantec.com/avcenter/threatcon/
"…A total of six buffer-overflow vulnerabilities that affect a number of widely distributed ActiveX controls have been disclosed in the past week. On February 3, 2008, additional high-profile ActiveX overflows were released by the same researcher who recently disclosed vulnerabilities in Aurigma Imaging Technology, MySpace, and Facebook image-upload ActiveX functions. Although very similar to the image-upload issues disclosed on January 31, 2008, these new ImageUploader issues are distinct and affect different properties. Note that the MySpace ImageUploader library has not been reported to be affected by these new vulnerabilities*. The remaining two vulnerabilities affect Yahoo! Jukebox MediaGrid and DataGrid ActiveX controls. We are unaware of any public exploitation of these vulnerabilities. However, the Symantec DeepSight team has confirmed that these issues can be used to execute code or crash the vulnerable applications. Judging by the wide distribution of these controls, we assume that these issues will be used by attackers and we are monitoring for such developments. Customers are advised to:
1. Set the kill bit for the following CLSIDs as soon as possible:
Aurigma: CLSID 6E5E167B-1566-4316-B27F-0DDAB3484CF7 ('ImageUploader4.ocx') ***
Aurigma: CLSID BA162249-F2C5-4851-8ADC-FC58CB424243 ('ImageUploader5') ***
Facebook: CLSID 5C6698D9-7BE4-4122-8EC5-291D84DBD4A0 **
Yahoo! MediaGrid: CLSID 22FD7C0A-850C-4A53-9821-0B0915C96139
Yahoo! DataGrid: CLSID 5F810AFC-BB5F-4416-BE63-E01DD117BD6C2
2. Take extreme caution when browsing the web.
3. Relay cautionary information to your users.
4. Ensure that browsers are configured with the highest security settings. Please see the following Microsoft support document for instructions on how to disable the ActiveX components: How to stop an ActiveX control from running in Internet Explorer
http://support.microsoft.com/kb/240797 …"
* Exception: http://secunia.com/advisories/28715
** Exception: http://secunia.com/advisories/28713/
*** Exception: Aurigma Image Uploader 4.x, Aurigma Image Uploader5.x
http://blogs.aurigma.com/post/2008/01/Anot…-not-again.aspx

> http://isc.sans.org/diary.html?storyid=3929
Last Updated: 2008-02-04 19:52:11 UTC (References Symantec info below)
- http://www.symantec.com/avcenter/threatcon/
"…A total of six buffer-overflow vulnerabilities that affect a number of widely distributed ActiveX controls have been disclosed in the past week. On February 3, 2008, additional high-profile ActiveX overflows were released by the same researcher who recently disclosed vulnerabilities in Aurigma Imaging Technology, MySpace, and Facebook image-upload ActiveX functions. Although very similar to the image-upload issues disclosed on January 31, 2008, these new ImageUploader issues are distinct and affect different properties. Note that the MySpace ImageUploader library has not been reported to be affected by these new vulnerabilities*. The remaining two vulnerabilities affect Yahoo! Jukebox MediaGrid and DataGrid ActiveX controls. We are unaware of any public exploitation of these vulnerabilities. However, the Symantec DeepSight team has confirmed that these issues can be used to execute code or crash the vulnerable applications. Judging by the wide distribution of these controls, we assume that these issues will be used by attackers and we are monitoring for such developments. Customers are advised to:
1. Set the kill bit for the following CLSIDs as soon as possible:
Aurigma: CLSID 6E5E167B-1566-4316-B27F-0DDAB3484CF7 ('ImageUploader4.ocx') ***
Aurigma: CLSID BA162249-F2C5-4851-8ADC-FC58CB424243 ('ImageUploader5') ***
Facebook: CLSID 5C6698D9-7BE4-4122-8EC5-291D84DBD4A0 **
Yahoo! MediaGrid: CLSID 22FD7C0A-850C-4A53-9821-0B0915C96139
Yahoo! DataGrid: CLSID 5F810AFC-BB5F-4416-BE63-E01DD117BD6C2
2. Take extreme caution when browsing the web.
3. Relay cautionary information to your users.
4. Ensure that browsers are configured with the highest security settings. Please see the following Microsoft support document for instructions on how to disable the ActiveX components: How to stop an ActiveX control from running in Internet Explorer
http://support.microsoft.com/kb/240797 …"
* Exception: http://secunia.com/advisories/28715
** Exception: http://secunia.com/advisories/28713/
*** Exception: Aurigma Image Uploader 4.x, Aurigma Image Uploader5.x
http://blogs.aurigma.com/post/2008/01/Anot…-not-again.aspx