Microsoft Internet Explorer Content Advisor File Handling Buffer Overflow Vulnerability
BID:13117
Info
Microsoft Internet Explorer Content Advisor File Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 13117 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0555 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2005 12:00AM |
| Updated: | Jul 12 2009 12:56PM |
| Credit: | Discovery is credited to Andres Tarasco of SIA Group. |
| Vulnerable: |
Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 5.0.1 SP3 Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 5.0.1 Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 5.5 SP2 Microsoft Internet Explorer 5.5 SP1 Microsoft Internet Explorer 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Content Advisor File Handling Buffer Overflow Vulnerability
Microsoft Internet Explorer is prone to a remote buffer overflow vulnerability when handling malformed Content Advisor files. An attacker can exploit this issue by crafting a Content Advisor file with excessive data and arbitrary machine code to be processed by the browser.
A typical attack would involve the attacker creating a Web site that includes the malicious file. A similar attack can also be carried out through HTML email using Microsoft Outlook and Microsoft Outlook Express applications.
It should be noted that successful exploitation requires the user to follow various steps to install a malicious file.
Microsoft Internet Explorer is prone to a remote buffer overflow vulnerability when handling malformed Content Advisor files. An attacker can exploit this issue by crafting a Content Advisor file with excessive data and arbitrary machine code to be processed by the browser.
A typical attack would involve the attacker creating a Web site that includes the malicious file. A similar attack can also be carried out through HTML email using Microsoft Outlook and Microsoft Outlook Express applications.
It should be noted that successful exploitation requires the user to follow various steps to install a malicious file.
Exploit / POC
Microsoft Internet Explorer Content Advisor File Handling Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Microsoft Internet Explorer Content Advisor File Handling Buffer Overflow Vulnerability
Solution:
Microsoft has released updates to address this vulnerability on supported platforms.
Internet Explorer 6 for Windows Server 2003 SP 1 including 64-Bit Edition is not affected by this issue. Windows XP Professional x64 Edition is also not affected.
Microsoft has released fixes for Windows 98, Windows 98 Second Edition, and Windows Millennium Edition. These updates are available from the Windows Update Web site:
http://go.microsoft.com/fwlink/?LinkId=21130
Localized Slovenian and Slovakian fixes are available for Windows 98, Windows 98 Second Edition, and Windows Millennium Edition as well. Please see the referenced Microsoft bulletin for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0 SP2 - do not use
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 5.0.1 SP3
Microsoft Internet Explorer 5.0.1 SP4
Solution:
Microsoft has released updates to address this vulnerability on supported platforms.
Internet Explorer 6 for Windows Server 2003 SP 1 including 64-Bit Edition is not affected by this issue. Windows XP Professional x64 Edition is also not affected.
Microsoft has released fixes for Windows 98, Windows 98 Second Edition, and Windows Millennium Edition. These updates are available from the Windows Update Web site:
http://go.microsoft.com/fwlink/?LinkId=21130
Localized Slovenian and Slovakian fixes are available for Windows 98, Windows 98 Second Edition, and Windows Millennium Edition as well. Please see the referenced Microsoft bulletin for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 6 Service Pack 1 for Windows XP & 2000 (KB890923)
Fix for Windows 2000 Service Pack 3, Windows 2000 Service Pack 4, and Windows XP Service Pack 1.
http://www.microsoft.com/downloads/details.aspx?familyid=92E5A83D-9131 -4B20-915A-A444C51656DC&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 64-bit Edition (KB890923)
Fix for Windows XP Service Pack 1 (64-Bit Edition).
http://www.microsoft.com/downloads/details.aspx?familyid=87241BC0-E1E9 -4EFC-A6EC-5413119D3100&displaylang=en
Microsoft Internet Explorer 6.0 SP2 - do not use
-
Microsoft Cumulative Security Update for Internet Explorer for XP Service Pack 2 (KB890923)
Fix for Windows XP Service Pack 2.
http://www.microsoft.com/downloads/details.aspx?familyid=974F9611-6352 -4F9C-B258-346C317857C5&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB890923)
Fix for Windows Server 2003.
http://www.microsoft.com/downloads/details.aspx?familyid=88879B7A-3F4D -40D4-ADFD-4BBD8D4D865F&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Edition (KB890923)
Fix for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003.
http://www.microsoft.com/downloads/details.aspx?familyid=FF80E80F-862A -4484-BC9D-FE05F966F1F4&displaylang=en
Microsoft Internet Explorer 5.0.1 SP3
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 3 (KB890923)
Fix for Windows 2000 Service Pack 3.
http://www.microsoft.com/downloads/details.aspx?familyid=6CF45449-03D8 -40B8-A4C0-09F413EE8EAB&displaylang=en
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 for Windows 2000 Service Pack 4 (KB890923)
Fix for Windows 2000 Service Pack 4.
http://www.microsoft.com/downloads/details.aspx?familyid=627F8991-7717 -4ADE-A5AE-169591B6AAE0&displaylang=en
References
Microsoft Internet Explorer Content Advisor File Handling Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS05-020 (Microsoft)