Izdana je revizija sigurnosnog upozorenja vezana uz Microsoft XML Editor, s oznakom MS11-049, koga je Microsoft prvotno objavio 14. lipnja 2011. U originalnoj je preporuci opisan propust koji može dovesti do otkrivanja osjetljivih informacija.
Paket:
Microsoft InfoPath 2010, Microsoft Office InfoPath 2007, Microsoft SQL Server 2005, Microsoft SQL Server 2008, Microsoft Visual Studio 2005, Microsoft Visual Studio 2008, Microsoft Visual Studio 2010
Operacijski sustavi:
Microsoft Windows Server 2003, Microsoft Windows Server 2008
Problem:
neodgovarajuće rukovanje datotekama
Iskorištavanje:
lokalno/udaljeno
Posljedica:
otkrivanje osjetljivih informacija
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-1280
Izvorni ID preporuke:
MS11-049
Izvor:
Microsoft
Problem:
Do propusta dolazi otvaranjem zlonamjerno oblikovanog Web Service Discovery (.disco) dokumenta. Revizija sigurnosnog upozorenja je izdana radi brisanja određenih ranjivih sustava iz polja "Non-Affected Software".
Posljedica:
Iskorištavanjem propusta napadači mogu otkriti i pregledavati potencijalno osjetljive podatke.
Rješenje:
Korisnici se potiču na primjenu dostupnih programskih rješenja.
Microsoft Security Bulletin MS11-049 - Important
Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)
Published: June 14, 2011 | Updated: June 15, 2011
Version: 1.2
General Information
Executive Summary
This security update resolves a privately reported vulnerability in Microsoft XML Editor. The vulnerability could allow information disclosure if a user opened a specially crafted Web Service Discovery (.disco) file with one of the affected software listed in this bulletin. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system.
This security update is rated Important for all supported editions of Microsoft InfoPath 2007 and Microsoft InfoPath 2010; all supported editions of SQL Server 2005, SQL Server 2008, and SQL Server 2008 R2; and all supported editions of Microsoft Visual Studio 2005, Microsoft Visual Studio 2008, and Microsoft Visual Studio 2010. For more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerability by correcting the manner in which the XML Editor resolves external entities within a Web Service Discovery (.disco) file. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
Recommendation. Microsoft recommends that customers apply the update at the earliest opportunity.
Known Issues. Microsoft Knowledge Base Article 2543893 documents the currently known issues that customers may experience when installing this security update. The article also documents recommended solutions for these issues.
Top of sectionTop of section
Affected and Non-Affected Software
The following software have been tested to determine which versions or editions are affected. Other versions or editions are either past their support life cycle or are not affected. To determine the support life cycle for your software version or edition, visit Microsoft Support Lifecycle.
Microsoft Office Software
Software Maximum Security Impact Aggregate Severity Rating Bulletins Replaced by this Update
Microsoft InfoPath 2007 Service Pack 2
(KB2510061)
Information Disclosure
Important
MS10-039
Microsoft InfoPath 2010 (32-bit editions)
(KB2510065)
Information Disclosure
Important
None
Microsoft InfoPath 2010 (64-bit editions)
(KB2510065)
Information Disclosure
Important
None
Microsoft SQL Server
GDR Software Updates QFE Software Updates Maximum Security Impact Aggregate Severity Rating Bulletins Replaced by this Update
SQL Server 2005 Service Pack 3
(KB2494113)
SQL Server 2005 Service Pack 3
(KB2494112)
Information Disclosure
Important
MS09-062
SQL Server 2005 x64 Edition Service Pack 3
(KB2494113)
SQL Server 2005 x64 Edition Service Pack 3
(KB2494112)
Information Disclosure
Important
MS09-062
SQL Server 2005 for Itanium-based Systems Service Pack 3
(KB2494113)
SQL Server 2005 for Itanium-based Systems Service Pack 3
(KB2494112)
Information Disclosure
Important
MS09-062
SQL Server 2005 Service Pack 4
(KB2494120)
SQL Server 2005 Service Pack 4
(KB2494123)
Information Disclosure
Important
None
SQL Server 2005 x64 Edition Service Pack 4
(KB2494120)
SQL Server 2005 x64 Edition Service Pack 4
(KB2494123)
Information Disclosure
Important
None
SQL Server 2005 for Itanium-based Systems Service Pack 4
(KB2494120)
SQL Server 2005 for Itanium-based Systems Service Pack 4
(KB2494123)
Information Disclosure
Important
None
SQL Server 2005 Express Edition Service Pack 3
(KB2494113)
SQL Server 2005 Express Edition Service Pack 3
(KB2494112)
Information Disclosure
Important
None
SQL Server 2005 Express Edition Service Pack 4
(KB2494120)
SQL Server 2005 Express Edition Service Pack 4
(KB2494123)
Information Disclosure
Important
None
SQL Server 2005 Express Edition with Advanced Services Service Pack 3
(KB2494113)
SQL Server 2005 Express Edition with Advanced Services Service Pack 3
(KB2494112)
Information Disclosure
Important
None
SQL Server 2005 Express Edition with Advanced Services Service Pack 4
(KB2494120)
SQL Server 2005 Express Edition with Advanced Services Service Pack 4
(KB2494123)
Information Disclosure
Important
None
SQL Server Management Studio Express (SSMSE) 2005
(KB2546869)
Not applicable
Information Disclosure
Important
None
SQL Server Management Studio Express (SSMSE) 2005 x64 Edition
(KB2546869)
Not applicable
Information Disclosure
Important
None
SQL Server 2008 for 32-bit Systems Service Pack 1
(KB2494096)
SQL Server 2008 for 32-bit Systems Service Pack 1
(KB2494100)
Information Disclosure
Important
None
SQL Server 2008 for x64-based Systems Service Pack 1
(KB2494096)
SQL Server 2008 for x64-based Systems Service Pack 1
(KB2494100)
Information Disclosure
Important
None
SQL Server 2008 for Itanium-based Systems Service Pack 1
(KB2494096)
SQL Server 2008 for Itanium-based Systems Service Pack 1
(KB2494100)
Information Disclosure
Important
None
SQL Server 2008 for 32-bit Systems Service Pack 2
(KB2494089)
SQL Server 2008 for 32-bit Systems Service Pack 2
(KB2494094)
Information Disclosure
Important
None
SQL Server 2008 for x64-based Systems Service Pack 2
(KB2494089)
SQL Server 2008 for x64-based Systems Service Pack 2
(KB2494094)
Information Disclosure
Important
None
SQL Server 2008 for Itanium-based Systems Service Pack 2
(KB2494089)
SQL Server 2008 for Itanium-based Systems Service Pack 2
(KB2494094)
Information Disclosure
Important
None
SQL Server 2008 R2 for 32-bit Systems
(KB2494088)
SQL Server 2008 R2 for 32-bit Systems
(KB2494086)
Information Disclosure
Important
None
SQL Server 2008 R2 for x64-based Systems
(KB2494088)
SQL Server 2008 R2 for x64-based Systems
(KB2494086)
Information Disclosure
Important
None
SQL Server 2008 R2 for Itanium-based Systems
(KB2494088)
SQL Server 2008 R2 for Itanium-based Systems
(KB2494086)
Information Disclosure
Important
None
Developer Tools
Software Maximum Security Impact Aggregate Severity Rating Bulletins Replaced by this Update
Microsoft Visual Studio 2005 Service Pack 1
(KB2251481)
Information Disclosure
Important
None
Microsoft Visual Studio 2008 Service Pack 1
(KB2251487)
Information Disclosure
Important
None
Microsoft Visual Studio 2010
(KB2251489)
Information Disclosure
Important
None
Non-Affected Software
Operating System
Microsoft InfoPath 2003 Service Pack 3
Microsoft SQL Server 2000 Desktop Engine Service Pack 4
Microsoft SQL Server 2000 Itanium Edition Service Pack 4
Microsoft SQL Server 2000 Reporting Services Service Pack 2
Microsoft SQL Server 2000 Service Pack 4
Microsoft Visual Studio .NET 2003 Service Pack 1
Top of sectionTop of section
Frequently Asked Questions (FAQ) Related to This Security Update
Vulnerability Information
Severity Ratings and Vulnerability Identifiers
XML External Entities Resolution Vulnerability - CVE-2011-1280
Update Information
Detection and Deployment Tools and Guidance
Security Update Deployment
Other Information
Acknowledgments
Microsoft thanks the following for working with us to help protect customers:
â
Posljednje sigurnosne preporuke