Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
BID:19667
CVE-2006-3869 |Info
Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
| Bugtraq ID: | 19667 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3869 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2006 12:00AM |
| Updated: | Mar 29 2007 12:43AM |
| Credit: | Reported by Derek Soeder of eEye and Dejan Kovacevic of Bold Internet Solutions. Independently discovered by Hu Qianwei of NSFocus Security Team. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
Microsoft Internet Explorer is prone to a remote buffer-overflow vulnerability. A successful exploit may result in arbitrary code-execution in the context of the user running the browser.
This issue was introduced with the patches released with Microsoft advisory MS06-042.
Internet Explorer 6 SP1 running on Microsoft Windows 2000 and Windows XP SP1 is vulnerable to this issue.
Microsoft Internet Explorer is prone to a remote buffer-overflow vulnerability. A successful exploit may result in arbitrary code-execution in the context of the user running the browser.
This issue was introduced with the patches released with Microsoft advisory MS06-042.
Internet Explorer 6 SP1 running on Microsoft Windows 2000 and Windows XP SP1 is vulnerable to this issue.
Exploit / POC
Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
Solution:
Microsoft Security Bulletin MS06-042 has been reissued to address this issue. Please see the referenced advisory for more information.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Microsoft Internet Explorer 6.0 SP1
Solution:
Microsoft Security Bulletin MS06-042 has been reissued to address this issue. Please see the referenced advisory for more information.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB918899)
Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 or on Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=C335CAA9-B9E6 -403D-A039-2D3DCA723653
References
Microsoft Internet Explorer HTTP 1.1 and Compression Long URI Buffer Overflow Vulnerability
References:
References:
- Internet Explorer 6 Service Pack 1 unexpectedly exits after you install the 9188 (Microsoft)
- KB926840: Internet Explorer 6 may close unexpectedly, and an access violation ma (Microsoft)
- Microsoft Security Advisory (923762) (Microsoft)
- MS06-042 - Cumulative Security Update for Internet Explorer (918899) (Microsoft)
- Researcher: Microsoft patch opens users to attack (Symantec)
- Vulnerability Note VU#821156 (US-CERT)
- EEYE: Internet Explorer Compressed Content URL Heap Overflow Vulnerability ("Marc Maiffret"
) - EEYE:ALERT: MS06-042 Related Internet Explorer 'Crash' is Exploitable ("Marc Maiffret"
) - NSFOCUS SA2006-08 : Microsoft IE6 urlmon.dll Long URL Buffer Overflow Vulnerabil (NSFOCUS Security Team
)