Microsoft Internet Explorer Element Tags Remote Memory Corruption Vulnerability
BID:26817
Info
Microsoft Internet Explorer Element Tags Remote Memory Corruption Vulnerability
| Bugtraq ID: | 26817 |
| Class: | Design Error |
| CVE: |
CVE-2007-5344 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2007 12:00AM |
| Updated: | Dec 21 2007 03:11AM |
| Credit: | Peter Vreugdenhil working with TippingPoint and the Zero Day Initiative is credited with the discovery of this issue. |
| Vulnerable: |
Nortel Networks W-NMS-UMTS 4.2 Nortel Networks W-NMS-CNM 1.0 Nortel Networks UMTS Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Multiservice Data Manager 0 Nortel Networks Multimedia Comm MCS5200 Nortel Networks Multimedia Comm MCS5100 Nortel Networks Enterprise VoIP TM-CS1000 Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Administration 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Element Tags Remote Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer Element Tags Remote Memory Corruption Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Internet Explorer Element Tags Remote Memory Corruption Vulnerability
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft IE6.0sp1-KB942615-Windows2000-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=BC8EDF05-262A -4D1D-B196-4FC1A844970C&displaylang=en -
Microsoft WindowsXP-KB942615-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=6E4EBAFC-34C3 -4DC7-B712-152C611D3F0A&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft WindowsServer2003-KB942615-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=B3F390A6-0361 -4553-B627-5E7AD6BF5055&displaylang=en -
Microsoft WindowsServer2003-KB942615-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=BF466060-A585 -4C2E-A48D-70E080C3BBE7&displaylang=en -
Microsoft WindowsServer2003.WindowsXP-KB942615-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=074697F2-18C8 -4521-BBF7-1D0E7395D27D&displaylang=en -
Microsoft WindowsServer2003.WindowsXP-KB942615-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=F5A5AF23-30FB -4E47-94BD-3B05B55C92F2 -
Microsoft WindowsXP-KB942615-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=6E4EBAFC-34C3 -4DC7-B712-152C611D3F0A&displaylang=en
References
Microsoft Internet Explorer Element Tags Remote Memory Corruption Vulnerability
References:
References:
- ASA-2007-513 - MS07-069 Cumulative Security Update for Internet Explorer (942615 (Avaya)
- Microsoft Internet Explorer Homepage (Microsoft)
- ZDI-07-075 Microsoft Internet Explorer Element Tags Vulnerability (Zero Day Initiative)
- ZDI-07-075: Microsoft Internet Explorer Element Tags Vulnerability ([email protected])
- MS Security Bulletin MS07-069 (Microsoft)
- Nortel Response to Microsoft Security Bulletin MS07-069 (Nortel Networks)