Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
BID:24811
Info
Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 24811 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-0043 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2007 12:00AM |
| Updated: | May 08 2009 04:26PM |
| Credit: | Jeroen Frijters of Sumatra is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft .NET Framework 2.0 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Customer Interaction Express (CIE) User Interface 1.0.2 Avaya Customer Interaction Express (CIE) User Interface 1.0 Avaya Customer Interaction Express (CIE) Server 1.0 Avaya CIE 1.0.2 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
Microsoft .NET Framework is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of a user running the application. Successful exploits can result in the complete compromise of affected computers. Failed attacks will likely result in denial-of-service conditions.
Microsoft .NET Framework is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of a user running the application. Successful exploits can result in the complete compromise of affected computers. Failed attacks will likely result in denial-of-service conditions.
Exploit / POC
Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released security bulletin MS07-040 as well as updates to address this issue. Please see the references for details.
Microsoft security bulletin MS07-040 has been revised; please see the referenced bulletin for details.
Microsoft security bulletin MS07-040 has been revised to include information regarding Pack 3 for .NET 1.0 and Service pack 1 for .NET Framework 1.1; please see the referenced bulletin for details.
Microsoft .NET Framework 2.0
Solution:
Microsoft has released security bulletin MS07-040 as well as updates to address this issue. Please see the references for details.
Microsoft security bulletin MS07-040 has been revised; please see the referenced bulletin for details.
Microsoft security bulletin MS07-040 has been revised to include information regarding Pack 3 for .NET 1.0 and Service pack 1 for .NET Framework 1.1; please see the referenced bulletin for details.
Microsoft .NET Framework 2.0
-
Microsoft KB928365 - .NET Framework 2.0 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Windows 2000, Windo
http://www.microsoft.com/downloads/details.aspx?FamilyId=BA3CEB78-8E1B -4C38-ADFD-E8BC95AE548D -
Microsoft KB929916 - .NET Framework 2.0 SYSTEM.WEB.DLL Security Update for Windows Vista
http://www.microsoft.com/downloads/details.aspx?FamilyId=CBC9F3CF-C3C3 -45C4-82E3-E11398BC2CD2
References
Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- ASA-2007-300 MS07-040 Vulnerabilities in .NET Framework Could Allow Remote Code (Avaya)
- Microsoft Security Bulletin MS07-040 (Microsoft)