Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
BID:21552
Info
Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 21552 |
| Class: | Design Error |
| CVE: |
CVE-2006-5579 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2006 12:00AM |
| Updated: | Apr 10 2007 08:31PM |
| Credit: | Discovery is credited to Jakob Balle and Carsten H. Eiram of Secunia Research. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance 2.1 Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya Messaging Application Server 0 |
| Not Vulnerable: |
Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 |
Discussion
Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
This vulnerability is related to how the browser handles script errors. An attacker may exploit this vulnerability to execute arbitrary code in the context of the user running the affected browser.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
This vulnerability is related to how the browser handles script errors. An attacker may exploit this vulnerability to execute arbitrary code in the context of the user running the affected browser.
Exploit / POC
Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
Solution:
Microsoft released a security bulletin and fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0 SP2 - do not use
Microsoft Internet Explorer 6.0
Solution:
Microsoft released a security bulletin and fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB925454)
http://www.microsoft.com/downloads/details.aspx?familyid=3CFC32FC-85CA -4EDA-890D-5E359F5F0019
Microsoft Internet Explorer 6.0 SP2 - do not use
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB925454)
http://www.microsoft.com/downloads/details.aspx?familyid=F56065CE-6D28 -479B-80A7-E04022454DE9&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB925454)
http://www.microsoft.com/downloads/details.aspx?familyid=3E3A9693-D21B -4214-A16C-3FC22340E600 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB925454) -
http://www.microsoft.com/downloads/details.aspx?familyid=9E3F7A2C-BFE1 -48C5-8A8A-64A06BCDF219 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 x64 Edition (KB925454)
http://www.microsoft.com/downloads/details.aspx?familyid=F56065CE-6D28 -479B-80A7-E04022454DE9 -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB925454)
http://www.microsoft.com/downloads/details.aspx?familyid=8B321744-B55E -4696-8B2C-B1D31672DA06 -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB925454)
http://www.microsoft.com/downloads/details.aspx?familyid=8D841D1B-D0B1 -46AF-87BD-7DAA8C31AF39
References
Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability
References:
References:
- ASA-2006-273 - MS06-072 Cumulative Security Update for Internet Explorer (925454 (Avaya)
- Critical Vulnerabilities in MS06-072 (IT-ISAC)
- Internet Explorer Script Error Handling Memory Corruption (Secunia Research)
- Microsoft Homepage (Microsoft)
- Microsoft Internet Explorer Homepage (Microsoft)
- Technical Cyber Security Alert TA06-346A - Microsoft Updates for Multiple Vulner (US-CERT)
- Vulnerability Note VU#599832 - Microsoft Internet Explorer Script Error Handling (US-CERT)
- Microsoft Security Bulletin MS06-072 (Microsoft)