|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2009-19

Microsoft Visual Studio Active Template Library (ATL) Multiple Vulnerabilities

Original Issue Date: July 29, 2009

Severity Rating: Medium

Affected Softwares

  • Microsoft Visual Studio .NET 2003 Service Pack 1
  • Microsoft Visual Studio 2005 Service Pack 1
  • Microsoft Visual Studio 2005 Service Pack 1 64-bit Hosted Visual C++ Tools
  • Microsoft Visual Studio 2008
  • Microsoft Visual Studio 2008 Service Pack 1
  • Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package
  • Microsoft Visual C++ 2008 Redistributable Package
  • Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package

Overview

Multiple vulnerabilities have been reported in Microsoft Active Template Library (ATL). Successful exploitation of these vulnerabilities could allow an attacker to execute an arbitrary code and take complete control of the affected system or cause the Information disclosure.

Overview

Multiple vulnerabilities have been reported in Opera, which can be exploited by an attacker to execute arbitrary code or conduct cross-site scripting attacks.

Description

  • Microsoft Active Template Library (ATL) Header Code Execution Vulnerability (CVE-2009-0901)

    This is a remote code execution vulnerability exists due to an error in ATL headers which allow an attacker to call the VariantClear function on an improperly initialized variant. A remote attacker could exploit this vulnerability to execute arbitrary code on the system.

  • Microsoft Active Template Library (ATL) COM Initialization Vulnerability (CVE-2009-2493)

    This is a remote code execution vulnerability exists due to an error in ATL headers when handling object instantiation from data streams related to unsafe usage of OleLoadFromStream function. A remote attacker could exploit this vulnerability to execute arbitrary code on the system.

  • Microsoft Active Template Library (ATL) Null String Information Disclosure Vulnerability (CVE-2009-2495)

    This vulnerability is caused due to an error in Microsoft ATL that allows reading a string without terminating null bytes. A remote attacker could obtain sensitive information by reading beyond end of string.

    Note: Microsoft has released security advisory (Microsoft security advisory 973822) to provide information about Active Template Library (ATL) vulnerabilities and guidance to developer, IT professional/ consumer and home users.

Workarounds

  • Apply appropriate patch as mentioned in Microsoft Security Bulletin - MS09-035

CVE Name

CVE-2009-0901
CVE-2009-2493
CVE-2009-2495

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Vendor Information

Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx

References

Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx

http://www.microsoft.com/technet/security/advisory/973882.mspx


ISS XForce
http://xforce.iss.net/


SecurityFocus
http://www.securityfocus.com/


Secunia
http://secunia.com/advisories/35967/


 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

10-Jul-2011