Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
BID:17468
Info
Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
| Bugtraq ID: | 17468 |
| Class: | Design Error |
| CVE: |
CVE-2006-1188 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2006 12:00AM |
| Updated: | May 26 2006 07:48PM |
| Credit: | Thomas Waldegger is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This is related to the handling of certain HTML tags.
Attackers could exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. They could also use HTML email for the attack.
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This is related to the handling of certain HTML tags.
Attackers could exploit this issue via a malicious web page to execute arbitrary code in the context of the currently logged-in user. They could also use HTML email for the attack.
Exploit / POC
Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept exploits are available to crash Internet Explorer:
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept exploits are available to crash Internet Explorer:
Solution / Fix
Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
Solution:
Microsoft has released a cumulative security update to address this issue. Updates for Internet Explorer on Windows 98/98SE/ME may be obtained through Windows Update.
Reportedly, the fixes provided in MS06-013 may cause unintended breakage with certain ActiveX controls. Symantec has not confirmed this. Before deploying this patch in production environments, test the patch thoroughly to ensure that it doesn't interfere with other software.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Solution:
Microsoft has released a cumulative security update to address this issue. Updates for Internet Explorer on Windows 98/98SE/ME may be obtained through Windows Update.
Reportedly, the fixes provided in MS06-013 may cause unintended breakage with certain ActiveX controls. Symantec has not confirmed this. Before deploying this patch in production environments, test the patch thoroughly to ensure that it doesn't interfere with other software.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB912812)
http://www.microsoft.com/downloads/details.aspx?familyid=033C41E1-2B36 -4696-987A-099FC57E0129&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB912812)
http://www.microsoft.com/downloads/details.aspx?familyid=033C41E1-2B36 -4696-987A-099FC57E0129&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB912812)
http://www.microsoft.com/downloads/details.aspx?familyid=EE566871-D217 -41D3-BECC-B27FAFA00054&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB912812) -
http://www.microsoft.com/downloads/details.aspx?familyid=E584957C-0ABE -4129-ABAF-AA2852AD62A3&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB912812) - English
http://www.microsoft.com/downloads/details.aspx?familyid=5A1C8BE3-39EE -4937-9BD1-280FC35125C6&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB912812)
http://www.microsoft.com/downloads/details.aspx?familyid=F05FFB31-E6B4 -4771-81F1-4ACCEBF72133&displaylang=en -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB912812)
http://www.microsoft.com/downloads/details.aspx?familyid=C278FE3E-620A -4BBC-868B-CA2D9EFF7AC3&displaylang=en
References
Microsoft Internet Explorer HTML Tag Memory Corruption Vulnerability
References:
References: