Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability
BID:11515
Info
Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11515 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1050 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | This issue was reported by ned <[email protected]> and Berend-Jan Wever <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya Modular Messaging S3400 Avaya IP600 Media Servers R9 Avaya IP600 Media Servers R8 Avaya IP600 Media Servers R7 Avaya IP600 Media Servers R6 Avaya IP600 Media Servers R12 Avaya IP600 Media Servers R11 Avaya IP600 Media Servers R10 Avaya IP600 Media Servers Avaya DefinityOne Media Servers R9 Avaya DefinityOne Media Servers R8 Avaya DefinityOne Media Servers R7 Avaya DefinityOne Media Servers R6 Avaya DefinityOne Media Servers R12 Avaya DefinityOne Media Servers R11 Avaya DefinityOne Media Servers R10 Avaya DefinityOne Media Servers |
| Not Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use |
Discussion
Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability
Microsoft Internet Explorer is reported prone to a remote buffer overflow vulnerability. This issue presents itself due to insufficient boundary checks performed by the application and results in arbitrary code execution or a denial of service.
This issue does not affect the following Internet Explorer 6 versions:
- Internet Explorer 6 for Windows Server 2003
- Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003
- Internet Explorer 6 for Windows XP Service Pack 2
Microsoft Internet Explorer is reported prone to a remote buffer overflow vulnerability. This issue presents itself due to insufficient boundary checks performed by the application and results in arbitrary code execution or a denial of service.
This issue does not affect the following Internet Explorer 6 versions:
- Internet Explorer 6 for Windows Server 2003
- Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003
- Internet Explorer 6 for Windows XP Service Pack 2
Exploit / POC
Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability
A proof of concept is available from the following location:
http://felinemenace.org/~nd/crash_ie/2446.html
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
An additional exploit has been made available by Berend-Jan Wever; the integrity of this exploit has not been verified by Symantec:
A proof of concept is available from the following location:
http://felinemenace.org/~nd/crash_ie/2446.html
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
An additional exploit has been made available by Berend-Jan Wever; the integrity of this exploit has not been verified by Symantec:
Solution / Fix
Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability
Solution:
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=212001&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Internet Explorer 6 Service Pack 2 is not prone to this vulnerability. If applicable, customers are advised to apply this service pack in order to mitigate the risk of exposure.
Microsoft has released a security bulletin that provides fixes for this issue on supported versions of the operating system. This bulletin also includes update rollup 889669 fixes for corporate users or users that have received hotfixes for Internet Explorer 6 SP1 after the release of bulletin MS04-004.
Microsoft Internet Explorer 6.0 SP1
Solution:
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=212001&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Internet Explorer 6 Service Pack 2 is not prone to this vulnerability. If applicable, customers are advised to apply this service pack in order to mitigate the risk of exposure.
Microsoft has released a security bulletin that provides fixes for this issue on supported versions of the operating system. This bulletin also includes update rollup 889669 fixes for corporate users or users that have received hotfixes for Internet Explorer 6 SP1 after the release of bulletin MS04-004.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for IE 6 SP1 (64-bit) for Corporations (889669)
http://www.microsoft.com/downloads/details.aspx?familyid=13a16832-769a -424e-9c4f-6188a7fccec0&displaylang=en -
Microsoft Cumulative Security Update for IE 6 SP1 for Corporations - Windows 98/ME/NT (889669)
http://www.microsoft.com/downloads/details.aspx?familyid=171d1ed7-bedd -40c8-b272-e457a2b020e3&displaylang=en -
Microsoft Cumulative Security Update for IE 6 SP1 for Corporations - Windows XP and Windows 2000 (889669)
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=c74028e2-10c9-4edd-ad0a-36493677bff8&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 6 Service Pack 1 for Windows XP & 2000 (KB889293)
This fix is for Internet Explorer 6 SP1 on Windows 2000 SP3 and SP4 as well as Windows XP SP1.
http://download.microsoft.com/download/b/a/c/bac5bccc-f2c3-40a3-b010-b 1c38cb2a963/IE6.0sp1-KB889293-Windows-2000-XP-x86-ENU.exe -
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 64-bit Edition (KB889293)
This fix is for Internet Explorer 6 SP1 on Windows XP 64-bit edition.
http://download.microsoft.com/download/9/b/8/9b8643eb-19f7-4049-96f8-e 72392564350/IE6.0sp1-KB889293-WindowsXP-ia64-ENU.exe -
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 for Windows 98, NT and ME (KB889293)
This fix is for Internet Explorer 6 SP1 on Windows 98, NT, and ME.
http://download.microsoft.com/download/5/2/6/526fbdb4-a46e-4b8a-bcf3-a f451acbf033/IE6.0sp1-KB889293-Windows-NT4sp6a-98-ME-x86-ENU.exe
References
Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability
References:
References:
- An update rollup is available for Internet Explorer 6 SP1 (Microsoft)
- Attacks and Exploits Report # 114 (Finjan Software)
- IE IFRAME Buffer Overflow exploit (CORE Security)
- Microsoft Security Bulletin MS04-040 (Microsoft)
- MSIE IFRAME and FRAME tag NAME property bufferoverflow PoC exploit (Michal Zalewski
) - python does mangleme (with IE bugs!) ("ned"
) - Re: python does mangleme (with IE bugs!) ("Berend-Jan Wever"
)