Buffer Overruns in Internet Explorer
Two unchecked buffers were discovered in Internet Explorer versions 5.01, 5.5, 6.0, and 6.0 for Windows Server 2003
June 4, 2003
Reported June 04, 2003, by Microsoft.
VERSIONS AFFECTED
MicrosoftInternet Explorer (IE) 6.0 for Windows Server 2003
MicrosoftIE 6.0, 5.5, 5.01
DESCRIPTION
Twonew vulnerabilities in Microsoft IE can result in the execution ofarbitrary code on the vulnerable system. These two new vulnerabilitiesare as follows:
Abuffer overrun vulnerability results from IE improperly determiningan object type that a Web server returns.
IEdoesn't implement an appropriate block on a file-download dialog box.
Ineach case, if a user visits a hostile Web site, an attacker can exploitthe vulnerability to run arbitrary code on the user's system withoutrequiring any other user action. The attacker can also craft an HTMLemail message to exploit these vulnerabilities.
VENDORRESPONSE
Microsoft has released SecurityBulletin MS03-020, "Cumulative Patch forInternet Explorer (818529)," to address these vulnerabilities andrecommends that affected users immediately apply the appropriate patchmentioned in the bulletin.
CREDIT
Discovered by eEye Digital Security.
About the Author
You May Also Like