Microsoft Internet Explorer CSS Tag Memory Corruption Vulnerability
BID:24423
Info
Microsoft Internet Explorer CSS Tag Memory Corruption Vulnerability
| Bugtraq ID: | 24423 |
| Class: | Unknown |
| CVE: |
CVE-2007-1750 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2007 12:00AM |
| Updated: | Jun 21 2007 10:39PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Nortel Networks Centrex IP Client Manager 8.0 Nortel Networks Centrex IP Client Manager 7.0 Nortel Networks Centrex IP Client Manager 9.0 Nortel Networks Centrex IP Client Manager Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance 2.1 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server 0 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CSS Tag Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability because the application fails to properly handle certain CSS data.
A remote attacker can exploit this issue to execute arbitrary code in the context of the user running the vulnerable application.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability because the application fails to properly handle certain CSS data.
A remote attacker can exploit this issue to execute arbitrary code in the context of the user running the vulnerable application.
Exploit / POC
Microsoft Internet Explorer CSS Tag Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Internet Explorer CSS Tag Memory Corruption Vulnerability
Solution:
Microsoft has released security bulletin MS07-033 with fixes to address this issue. Please see the referenced bulletin for information on obtaining fixes.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Solution:
Microsoft has released security bulletin MS07-033 with fixes to address this issue. Please see the referenced bulletin for information on obtaining fixes.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Update for Internet Explorer 6 SP1 (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5C958650-28D2 -4DD0-96A8-DBFE79CE3F68 -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7ED19127-5C2D -48E4-A8D1-090DC69FD68B -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=B628A3CC-A70C -478A-A10C-EEE254EE34AB -
Microsoft Cumulative Update for Internet Explorer for Windows XP Service Pack 2 (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=60FB294E-A8E1 -405E-A289-2D2723EDF7EE -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=086D6D6E-4703 -4C6C-A7AF-B6DAFEEEDE5D
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7ED19127-5C2D -48E4-A8D1-090DC69FD68B -
Microsoft Cumulative Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=B628A3CC-A70C -478A-A10C-EEE254EE34AB -
Microsoft Cumulative Update for Internet Explorer for Windows XP x64 Edition (KB933566)
http://www.microsoft.com/downloads/details.aspx?FamilyId=086D6D6E-4703 -4C6C-A7AF-B6DAFEEEDE5D
References
Microsoft Internet Explorer CSS Tag Memory Corruption Vulnerability
References:
References: