Buffer Overruns in Internet Explorer

Two unchecked buffers were discovered in Internet Explorer versions 5.01, 5.5, 6.0, and 6.0 for Windows Server 2003

Ken Pfeil

June 4, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported June 04, 2003, by Microsoft.


VERSIONS AFFECTED
 

  • MicrosoftInternet Explorer (IE) 6.0 for Windows Server 2003

  • MicrosoftIE 6.0, 5.5, 5.01

DESCRIPTION

Twonew vulnerabilities in Microsoft IE can result in the execution ofarbitrary code on the vulnerable system. These two new vulnerabilitiesare as follows:

  • Abuffer overrun vulnerability results from IE improperly determiningan object type that a Web server returns.

  • IEdoesn't implement an appropriate block on a file-download dialog box.

Ineach case, if a user visits a hostile Web site, an attacker can exploitthe vulnerability to run arbitrary code on the user's system withoutrequiring any other user action. The attacker can also craft an HTMLemail message to exploit these vulnerabilities.

VENDORRESPONSE

Microsoft has released SecurityBulletin MS03-020, "Cumulative Patch forInternet Explorer (818529)," to address these vulnerabilities andrecommends that affected users immediately apply the appropriate patchmentioned in the bulletin.

CREDIT

Discovered by eEye Digital Security.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like