[SECURITY-L] CAIS-Alerta: Correcoes de Seguranca Acumulativas para Internet Explorer (MS08-031)

CSIRT - UNICAMP security em unicamp.br
Qui Jun 12 09:34:00 -03 2008


----- Forwarded message from Centro de Atendimento a Incidentes de Seguranca <cais em cais.rnp.br> -----

From: Centro de Atendimento a Incidentes de Seguranca <cais em cais.rnp.br>
Subject:  CAIS-Alerta: Correcoes de Seguranca Acumulativas para Internet
 Explorer (MS08-031)
To: pop-seg em cais.rnp.br, rnp-alerta em cais.rnp.br, rnp-seg em cais.rnp.br
Date: Wed, 11 Jun 2008 11:47:01 -0300 (BRT)

-----BEGIN PGP SIGNED MESSAGE-----


Prezados,

O CAIS esta' repassando o alerta da Microsoft, intitulado "MS08-031 - 
Cumulative Security Update for Internet Explorer (950759)", que trata de 
duas vulnerabilidades recem identificadas no navegador Internet Explorer.

As vulnerabilidades foram classificadas como criticas pela Microsoft e 
permitem a execucao remota de codigo caso um usuario abra uma pagina Web 
maliciosa com um navegador Internet Explorer afetado. Usuarios cujas 
contas tenham menos privilegios no sistema podem sofrer menos impacto.


Sistemas afetados:

. Internet Explorer 5.01
  - Microsoft Windows 2000 Service Pack 4

. Internet Explorer 6 Service Pack 1
  - Microsoft Windows 2000 Service Pack 4

. Internet Explorer 6
  - Windows XP Service Pack 2
  - Windows XP Service Pack 3
  - Windows XP Professional x64 Edition
  - Windows XP Professional x64 Edition Service Pack 2
  - Windows Server 2003 Service Pack 1
  - Windows Server 2003 Service Pack 2
  - Windows Server 2003 x64 Edition
  - Windows Server 2003 x64 Edition Service Pack 2
  - Windows Server 2003 com SP1 para sistemas baseados em Itanium
  - Windows Server 2003 com SP2 para sistemas baseados em Itanium

. Internet Explorer 7
  - Windows XP Service Pack 2
  - Windows XP Service Pack 3
  - Windows XP Professional x64 Edition
  - Windows XP Professional x64 Edition Service Pack 2
  - Windows Server 2003 Service Pack 1
  - Windows Server 2003 Service Pack 2
  - Windows Server 2003 x64 Edition
  - Windows Server 2003 x64 Edition Service Pack 2
  - Windows Server 2003 com SP1 para sistemas baseados em Itanium
  - Windows Server 2003 com SP2 para sistemas baseados em Itanium
  - Windows Vista
  - Windows Vista Service Pack 1
  - Windows Vista x64 Edition
  - Windows Vista x64 Edition Service Pack 1
  - Windows Server 2008 para sistemas 32-bit
  - Windows Server 2008 para sistemas x64
  - Windows Server 2008 para sistemas baseados em Itanium


Correcoes disponiveis:

Recomenda-se fazer a atualizacao para as versoes disponiveis em:

. Internet Explorer 5.01

  - Microsoft Windows 2000 Service Pack 4
    http://www.microsoft.com/downloads/details.aspx?FamilyId=88990B23-D37F-4D02-A5A3-2EE389ADE53C

. Internet Explorer 6 Service Pack 1

  - Microsoft Windows 2000 Service Pack 4
    http://www.microsoft.com/downloads/details.aspx?FamilyId=4C47CF8A-8100-4D43-855A-F225A3492B19

. Internet Explorer 6

  - Windows XP Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=CC325017-3A48-4475-90E4-0C79A002FCE3

  - Windows XP Service Pack 3
    http://www.microsoft.com/downloads/details.aspx?FamilyId=CC325017-3A48-4475-90E4-0C79A002FCE3

  - Windows XP Professional x64 Edition
    http://www.microsoft.com/downloads/details.aspx?FamilyId=C8783CFE-9DA5-4842-AB3A-1E2BE4FAFC47

  - Windows XP Professional x64 Edition Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=C8783CFE-9DA5-4842-AB3A-1E2BE4FAFC47

  - Windows Server 2003 Service Pack 1
    http://www.microsoft.com/downloads/details.aspx?FamilyId=286AADA6-A358-41F1-B81A-8DE39B9F908A

  - Windows Server 2003 Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=286AADA6-A358-41F1-B81A-8DE39B9F908A

  - Windows Server 2003 x64 Edition
    http://www.microsoft.com/downloads/details.aspx?FamilyId=6604569A-3DB0-47E7-BD30-7DFBA8145386

  - Windows Server 2003 x64 Edition Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=6604569A-3DB0-47E7-BD30-7DFBA8145386

  - Windows Server 2003 com SP1 para sistemas baseados em Itanium
    http://www.microsoft.com/downloads/details.aspx?FamilyId=0262BEB8-1EB5-4C2D-A50A-0C6C6E0C1F61

  - Windows Server 2003 com SP2 para sistemas baseados em Itanium
    http://www.microsoft.com/downloads/details.aspx?FamilyId=0262BEB8-1EB5-4C2D-A50A-0C6C6E0C1F61

. Internet Explorer 7

  - Windows XP Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=FBC31BDE-0BF5-490C-96A8-071310D9464A

  - Windows XP Service Pack 3
    http://www.microsoft.com/downloads/details.aspx?FamilyId=FBC31BDE-0BF5-490C-96A8-071310D9464A

  - Windows XP Professional x64 Edition
    http://www.microsoft.com/downloads/details.aspx?FamilyId=19C0CCDC-95C9-4151-96B6-4F49B594EBE0

  - Windows XP Professional x64 Edition Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=19C0CCDC-95C9-4151-96B6-4F49B594EBE0

  - Windows Server 2003 Service Pack 1
    http://www.microsoft.com/downloads/details.aspx?FamilyId=A1AE9AD2-8329-4C96-B950-7534B3287EAA

  - Windows Server 2003 Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=A1AE9AD2-8329-4C96-B950-7534B3287EAA

  - Windows Server 2003 x64 Edition
    http://www.microsoft.com/downloads/details.aspx?FamilyId=FB0C70B4-CE9F-43D6-875A-3CFD0D3A2681

  - Windows Server 2003 x64 Edition Service Pack 2
    http://www.microsoft.com/downloads/details.aspx?FamilyId=FB0C70B4-CE9F-43D6-875A-3CFD0D3A2681

  - Windows Server 2003 com SP1 para sistemas baseados em Itanium
    http://www.microsoft.com/downloads/details.aspx?FamilyId=28D2913C-1C6B-4671-9892-DE08698CD5A6

  - Windows Server 2003 com SP2 para sistemas baseados em Itanium
    http://www.microsoft.com/downloads/details.aspx?FamilyId=28D2913C-1C6B-4671-9892-DE08698CD5A6

  - Windows Vista
    http://www.microsoft.com/downloads/details.aspx?FamilyId=6D68B39D-157F-4C3D-AC76-BC5A9386DB59

  - Windows Vista Service Pack 1
    http://www.microsoft.com/downloads/details.aspx?FamilyId=6D68B39D-157F-4C3D-AC76-BC5A9386DB59

  - Windows Vista x64 Edition
    http://www.microsoft.com/downloads/details.aspx?FamilyId=4CF92235-861E-4B74-BEE3-8E977C8688D9

  - Windows Vista x64 Edition Service Pack 1
    http://www.microsoft.com/downloads/details.aspx?FamilyId=4CF92235-861E-4B74-BEE3-8E977C8688D9

  - Windows Server 2008 para sistemas 32-bit
    http://www.microsoft.com/downloads/details.aspx?FamilyId=A8922E7E-9264-4E09-B8AD-C5420FED8690

  - Windows Server 2008 para sistemas x64
    http://www.microsoft.com/downloads/details.aspx?FamilyId=05B0E838-24D7-4387-B069-2604BBCC43B9

  - Windows Server 2008 para sistemas baseados em Itanium
    http://www.microsoft.com/downloads/details.aspx?FamilyId=640E1865-EBCC-4D69-A770-FD360020DA1E


Mais informacoes:

. MS08-031 - Cumulative Security Update for Internet Explorer (950759)
  http://www.microsoft.com/technet/security/bulletin/ms08-031.mspx

. SANS ISC Handler's Diary 2008-06-10: June 2008 Black Tuesday Overview
  http://isc.sans.org/diary.html?storyid=4552

. Microsoft Brasil Security
  http://www.microsoft.com/brasil/security

. Technet Brasil - Central de Seguranca
  http://www.technetbrasil.com.br/seguranca

. Windows Live OneCare
  http://safety.live.com/site/pt-BR/default.htm


Identificador CVE (http://cve.mitre.org): CVE-2008-1442, CVE-2008-1544


O CAIS recomenda que os administradores mantenham seus sistemas e 
aplicativos sempre atualizados, de acordo com as ultimas versoes e 
correcoes oferecidas pelos fabricantes.


Os Alertas do CAIS tambem sao oferecidos no formato RSS/RDF:
http://www.rnp.br/cais/alertas/rss.xml


Atenciosamente,

################################################################
#   CENTRO DE ATENDIMENTO A INCIDENTES DE SEGURANCA (CAIS)     #
#       Rede Nacional de Ensino e Pesquisa (RNP)               #
#                                                              #
# cais em cais.rnp.br       http://www.cais.rnp.br                #
# Tel. 019-37873300      Fax. 019-37873301                     #
# Chave PGP disponivel   http://www.rnp.br/cais/cais-pgp.key   #
################################################################
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Made with pgp4pine 1.76

iQCVAwUBSE/laukli63F4U8VAQFmIQQApbHWr6JO7GBdOUsrbeZpKGns4kKXZv2d
tSHqhhZ+59uJ7RlHlTdEgpbEIxxCaO8AbMBm2EG90z9JylvL8hOFyhTZ31J7JBIn
TiFfL6hZi7TJ4uxrT9RpPebLneKcrU6gTIls340I6s5/LzFcSt9FlZLSj4nLGIpe
BF1X1DDukmk=
=qKBX
-----END PGP SIGNATURE-----


----- End forwarded message -----



Mais detalhes sobre a lista de discussão SECURITY-L