[SECURITY-L] CAIS-Alerta: Vulnerabilidade no Servico de Log de Licensa (MS05-010)

CSIRT - UNICAMP security em unicamp.br
Ter Fev 15 08:59:37 -02 2005


----- Forwarded message from Centro de Atendimento a Incidentes de Seguranca <cais em cais.rnp.br> -----

From: Centro de Atendimento a Incidentes de Seguranca <cais em cais.rnp.br>
Subject:  CAIS-Alerta: Vulnerabilidade no Servico de Log de Licensa (MS05-010)
To: rnp-alerta em cais.rnp.br, rnp-seg em cais.rnp.br
Date: Fri, 11 Feb 2005 14:56:09 -0200 (BRDT)

-----BEGIN PGP SIGNED MESSAGE-----


Prezados,

O CAIS esta' repassando o alerta da Microsoft, intitulado "MS05-010 - 
Vulnerability in the License Logging Service Could Allow Code Execution 
(885834)", que trata de uma vulnerabilidade recem-descoberta no servico de 
log de licensas.

Um atacante que explorar esta vulnerabilidade pode obter controle completo 
sobre o sistema afetado, podendo instalar programas, criar novas contas de 
usuarios com privilegios totais do sistema ou ate' mesmo visualizar, 
modificar ou apagar dados no sistema vulneravel.


Sistemas afetados:

. Microsoft Windows NT Server 4.0 Service Pack 6a
. Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
. Microsoft Windows 2000 Server Service Pack 3
. Microsoft Windows 2000 Server Service Pack 4
. Microsoft Windows Server 2003
. Microsoft Windows Server 2003 for Itanium-based Systems


Correcoes disponiveis:

Recomenda-se fazer a atualizacao para as versoes disponiveis em:

. Microsoft Windows NT Server 4.0 Service Pack 6a          
  http://www.microsoft.com/downloads/details.aspx?FamilyId=817FDC2D-AEE2-4FAF-908B-197B65A471F2
                                                                                   
. Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6                                                                      
  http://www.microsoft.com/downloads/details.aspx?FamilyId=F7B0934C-3049-4B01-956A-B116F69A667E

. Microsoft Windows 2000 Server Service Pack 3                                                                                                
  http://www.microsoft.com/downloads/details.aspx?FamilyId=E9983AA2-2CEC-4B62-80D6-8E966A83A5D1

. Microsoft Windows 2000 Server Service Pack 4                                                                                                
  http://www.microsoft.com/downloads/details.aspx?FamilyId=E9983AA2-2CEC-4B62-80D6-8E966A83A5D1

. Microsoft Windows Server 2003                                                                                                               
  http://www.microsoft.com/downloads/details.aspx?FamilyId=06EAF8E3-CCB7-482B-8B68-340521150113

. Microsoft Windows Server 2003 for Itanium-based Systems  
  http://www.microsoft.com/downloads/details.aspx?FamilyId=EC25EC00-9C08-4555-94C7-21D5A521FDB6


Mais informacoes:

. MS05-010 - Vulnerability in the License Logging Service Could Allow Code Execution (885834) 
  http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx

. Vulnerability Note VU#130433 - Microsoft License Logging Service buffer overflow
  http://www.kb.cert.org/vuls/id/130433

. Microsoft Brasil Security
  http://www.microsoft.com/brasil/security

. Technet Brasil - Central de Seguranca
  http://www.technetbrasil.com.br/seguranca


Identificador CVE (http://cve.mitre.org): CAN-2005-0050


O CAIS recomenda que os administradores mantenham seus sistemas e 
aplicativos sempre atualizados, de acordo com as ultimas versoes e 
correcoes oferecidas pelos fabricantes.

Os Alertas do CAIS tambem sao oferecidos no formato RSS/RDF:
http://www.rnp.br/cais/alertas/rss.xml


Atenciosamente,

################################################################
#   CENTRO DE ATENDIMENTO A INCIDENTES DE SEGURANCA (CAIS)     #
#       Rede Nacional de Ensino e Pesquisa (RNP)               #
#                                                              #
# cais em cais.rnp.br       http://www.cais.rnp.br                #
# Tel. 019-37873300      Fax. 019-37873301                     #
# Chave PGP disponivel   http://www.rnp.br/cais/cais-pgp.key   #
################################################################

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.8

iQCVAwUBQgzjr+kli63F4U8VAQHCcQQAwBZs8gg+3PzTY/DxXffWckaIeAqvnRrR
2TqmMx43AP2DDMAaPeh4Yaz7WaoEQvhLDVw/vCemznewOJfaYl/hY79TF0B8t7d7
HOd+NgGVhZE3o1RoWxmvUCHXT5hQzrLqYxMiKMxX9qrZ08zZtbtTKabmxJwqcVqn
mnVCn1Sc59Y=
=xbio
-----END PGP SIGNATURE-----


----- End forwarded message -----



Mais detalhes sobre a lista de discussão SECURITY-L