Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
BID:19312
CVE-2006-3450 |Info
Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
| Bugtraq ID: | 19312 |
| Class: | Unknown |
| CVE: |
CVE-2006-3450 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Mar 29 2007 12:53AM |
| Credit: | Discovery is credited to Sam Thomas. |
| Vulnerable: |
Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center - Agent Desktop Display 0 Nortel Networks Centrex IP Element Manager 0 Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 5.0.1 SP3 Microsoft Internet Explorer 5.0.1 SP2 Microsoft Internet Explorer 5.0.1 SP1 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Microsoft Internet Explorer 5.0.1 SP4 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
This vulnerability is related to how the browser renders HTML with certain layout and positioning combinations. An attacker could exploit this issue to execute arbitrary code in the context of the user visiting a malicious web page.
This issue affects Internet Explorer on Windows 2000, Windows XP, and Windows Server 2003.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
This vulnerability is related to how the browser renders HTML with certain layout and positioning combinations. An attacker could exploit this issue to execute arbitrary code in the context of the user visiting a malicious web page.
This issue affects Internet Explorer on Windows 2000, Windows XP, and Windows Server 2003.
Exploit / POC
Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
Solution:
Microsoft has released a security bulletin to address this issue. Please see the referenced security bulletin for details.
MS06-042 has been reissued to address a vulnerability introduced with the previous fixes. Please see BID 19667 (Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability) for further information on this issue.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 5.0.1 SP4
Solution:
Microsoft has released a security bulletin to address this issue. Please see the referenced security bulletin for details.
MS06-042 has been reissued to address a vulnerability introduced with the previous fixes. Please see BID 19667 (Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability) for further information on this issue.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB918899)
Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 or on Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=C335CAA9-B9E6 -403D-A039-2D3DCA723653 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=5C2A23AC-3F2E -4BEC-BE16-4B45B44C6346 -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=0CE7F66D-4D83 -4090-A034-9BBE286D96FA
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
http://www.microsoft.com/downloads/details.aspx?familyid=20288DA2-A308 -45C6-BD80-C68C997529BD -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?familyid=663F1E83-BDC0 -4EC6-A263-398E7222C9B5 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=5C2A23AC-3F2E -4BEC-BE16-4B45B44C6346 -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB918899)
Internet Explorer 6 for Microsoft Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?familyid=CDB85BCA-0C17 -44AA-B74E-F01B5392BB31 -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB918899)
Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=0CE7F66D-4D83 -4090-A034-9BBE286D96FA
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Cumulative Update for Internet Explorer 5.01 Service Pack 4 (KB918899)
Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?familyid=0DE3F143-19A6 -4F22-B53B-B6A7DA33DAF4
References
Microsoft Internet Explorer HTML Layout and Positioning Remote Code Execution Vulnerability
References:
References:
- BULLETIN - 2006007223 ] NORTEL RESPONSE TO MICROSOFT SECURITY BULLETIN MS06-042 (Nortel)
- KB926840: Internet Explorer 6 may close unexpectedly, and an access violation ma (Microsoft)
- MS06-042 - Cumulative Security Update for Internet Explorer (918899) (Microsoft)
- ZDI-06-027: Microsoft Internet Explorer CSS Class Ordering Memory Corruption Vul (Zero Day Initiative (ZDI))