Microsoft Black Tuesday - October 2006 - Michael Sutton's Blog -
Microsoft Black Tuesday - October 2006

And the file format vulnerabilities keep on coming! If the 2006 Microsoft security bulletins have had a theme, that theme has been file format vulnerabilities in media formats and Office documents. We kicked off 2006 with an out of cycle patch for the famed WMF vulnerability and during the past few months we’ve been inundated with patches for Excel, Word and PowerPoint among others.

This month’s bulletins included a handful of patches for public vulnerabilities for which Microsoft had already released security advisories. The following security advisories received patches:

These follow the out of cycle patch in Vector Markup Language, which was released on September 26, 2006 in MS06-055.

I hope that you were able to get a good break last month when Microsoft had an uncharacteristically light month with three security bulletins because it’s now time to get back to work. The October edition of Microsoft Black Tuesday greeted us with a total of 26 vulnerabilities in ten bulletins with 15 of the bulletins receiving a critical severity ranking.

It looks like there were a few hiccups with this month’s release. First off, the advance notification suggested that we would see eleven vulnerabilities, yet, we only saw ten. It isn’t clear if two bulletins were combined into one or if one was pulled at the last minute.  Also, in the MSRC blog posting, Craig Gehre admitting to some networking issues that lead to automatic updates not being pushed out at the same time that the security bulletins were posted. No specifics were provided for either issue other that an acknowledgement that Microsoft is aware of the networking issues and is working to resolve them before the next release. Fortunately, the patches were available for a manual download once the bulletins were made available.

Below is a cheat sheet for all 26 vulnerabilities.

Enjoy!

- michael

 

Bulletin

Title

Public

Exploited

MS06-056

 

.NET Framework 2.0 Cross-Site Scripting Vulnerability
CVE-2006-3436
Moderate
Discovered By: Jaswinder Hayre

No

No

MS06-057

Windows Shell Remote Code Execution Vulnerability
CVE-2006-3730
Critical
Discovered By: HD Moore
Exploit: ie_webview_setslice.pm

Yes

Yes

MS06-058

PowerPoint Malformed Object Pointer Vulnerability
CVE-2006-3435
Important
Discovered By: Arnaud Dovi working and ZDI

No

No

MS06-058

PowerPoint Malformed Data Record Vulnerability
CVE-2006-3876
Critical
Discovered By: Dejun Meng of Fortinet Inc.

No

No

MS06-058

PowerPoint Malformed Record Memory Corruption Vulnerability
CVE-2006-3877
Critical
Discovered By:

No

No

MS06-058

PowerPoint Malformed Record Vulnerability
CVE-2006-4694
Critical
Discovered By: Chris Ries of VigilantMinds Inc.

Yes

Yes

MS06-059

Excel Malformed DATETIME Record Vulnerability
CVE-2006-2387
Critical
Discovered By:Manuel Santamarina Suarez and ZDI

No

No

MS06-059

Excel Malformed STYLE Record Vulnerability
CVE-2006-3431
Critical
Discovered By:
Exploit: Nanika.xls

Yes

No

MS06-059

Excel Handling of Lotus 1-2-3 File Vulnerability
CVE-2006-3867
Critical
Discovered By:

Yes

No

MS06-059

Excel Malformed COLINFO Record Vulnerability
CVE-2006-3875
Critical
Discovered By: NSFocus Security Team

No

No

MS06-060

Microsoft Word Vulnerability
CVE-2006-3647
Critical
Discovered By: Chen Xiaobo of McAfee Avert Labs

No

No

MS06-060

Microsoft Word Mail Merge Vulnerability
CVE-2006-3651
Critical
Discovered By: Cu Fang

No

No

MS06-060

Microsoft Word Malformed Stack Vulnerability
CVE-2006-4534
Critical
Discovered By:

Yes

Yes

MS06-060

Microsoft Word for Mac Vulnerability
CVE-2006-4693
Important
Discovered By:

No

No

MS06-061

Microsoft XML Core Services Vulnerability
CVE-2006-4685
Important
Discovered By: Cu Fang

No

 

MS06-061

XSLT Buffer Overrun Vulnerability
CVE-2006-4686
Critical
Discovered By:

No

 

MS06-062

Office Improper Memory Access Vulnerability
CVE-2006-3434
Critical
Discovered By: Dejun Meng of Fortinet Inc.

No

No

MS06-062

Office Malformed Chart Record Vulnerability
CVE-2006-3650
Critical
Discovered By: Arnaud Dovi and ZDI

No

No

MS06-062

Office Malformed Record Memory Corruption Vulnerability
CVE-2006-3864
Critical
Discovered By: Sowhat of Nevis Labs

No

No

MS06-062

Microsoft Office Smart Tag Parsing Vulnerability
CVE-2006-3868
Important
Discovered By:

Yes

No

MS06-063

Server Service Denial of Service Vulnerability
CVE-2006-3942
Important
Discovered By: Ivan Acre of Core Impact and NS Focus
Exploit: MS06_035-aug222006.c

Yes

No

MS06-063

SMB Rename Vulnerability
CVE-2006-4696
Important
Discovered By:Fortinet and Matthew Amdur of VMWare

No

No

MS06-064

ICMP Connection Reset Vulnerability
CVE-2004-0790
Low
Discovered By:

Yes

No

MS06-064

TCP Connection Reset Vulnerability
CVE-2004-0230
Low
Discovered By:

Yes

No

MS06-064

Spoofed Connection Request Vulnerability
CVE-2005-0688
Low
Discovered By:

Yes

No

MS06-065

Object Packager Dialogue Spoofing Vulnerability
CVE-2006-4692
Moderate
Discovered By: Andreas Sandblad of Secunia Research

No

No


Posted 10-10-2006 8:33 PM by erik.peterson