CERT-In Vulnerability Note
CIVN-2005-0102
Microsoft Collaboration Data Objects Buffer Overflow Vulnerability
Original Issue Date:October 13, 2005
Severity Rating: MEDIUM
Systems Affected
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
- Microsoft Exchange 2000 Server Service Pack 3 with the Exchange 2000 Post-Service Pack 3 Update Rollup of August 2004
Overview
A buffer overflow vulnerability exists in Microsoft Collaboration Data Objects which may allow a remote attacker to execute arbitrary code to compromise a vulnerable system.
Description
Microsofts Collaboration Data Objects CDO is an additional scripting interface to existing Microsoft messaging model and is used to make it easier to write programs that create or change Internet mail messages. The vulnerability is due to a stack overflow in Collaboration Data Objects CDO when parsing email content by using event sinks.
This could be exploited via a specially crafted email message and when it is processed by CDO triggers buffer overflow, consequently executes the arbitrary code. An attacker who successfully exploits this vulnerability could take complete control of the system.
Workaround
Microsoft suggested following workarounds to mitigate the attack vectors. - Disable all event sinks that are enabled on Exchange 2000 Server and on servers that are running IIS
- Unregister the Cdoex.dll file and the Cdosys.dll file on Exchange 2000 Server and unregister the Cdosys.dll file on servers that are running IIS
For more information on workaround refer to MS05-048
Solution
Apply appropriate security update as mentioned in the Microsoft Security Bulletin
MS05-048
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS05-048.mspx
References
Microsoft Security Bulletin MS05-048
http://www.microsoft.com/technet/security/bulletin/MS05-048.mspx
Secunia Advisory
http://secunia.com/advisories/17167/
US-CERT VU#883460
http://www.kb.cert.org/vuls/id/883460
CVE Name
CAN-2005-1987
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|