Microsoft Internet Explorer Property Method Remote Memory Corruption Vulnerability
BID:27666
Info
Microsoft Internet Explorer Property Method Remote Memory Corruption Vulnerability
| Bugtraq ID: | 27666 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0077 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Mar 25 2008 06:00PM |
| Credit: | An anonymous researcher working with TippingPoint and the Zero Day Initiative and hyy working with VeriSign iDefense VCP are credited with the discovery of this vulnerability. |
| Vulnerable: |
Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Express Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager 9.0 Nortel Networks Centrex IP Client Manager 10.0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Property Method Remote Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer Property Method Remote Memory Corruption Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Internet Explorer Property Method Remote Memory Corruption Vulnerability
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 (KB944533)
http://www.microsoft.com/downloads/details.aspx?FamilyId=87E66DCE-5060 -4814-8754-829B4E190359&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB944533)
http://www.microsoft.com/downloads/details.aspx?FamilyId=429B7ED1-FE78 -459A-B834-D0F3C69CB703&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB944533)
http://www.microsoft.com/downloads/details.aspx?FamilyId=E989E23C-38BB -4FE7-A830-D7BDF7659392&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP Service Pack 2 (KB944533)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BB2AA3CB-021F -4890-AB20-2A51F8E17554&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB944533)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8989F576-8B30 -4866-90EC-929D24F3B409&displaylang=en
References
Microsoft Internet Explorer Property Method Remote Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Internet Explorer Property Memory Corruption Vulnerability (iDefense Labs)
- iDefense Security Advisory 02.12.08: Microsoft Internet Explorer Property Memory (iDefense Labs
) - 2008008629: Nortel Response to Microsoft Security Bulletin MS08-010Nortel Resp (Nortel Networks)
- Centrex IP Client Manager (CICM) Response to Microsoft February 2008 Security Bu (Nortel Networks)
- Microsoft Security Bulletin MS08-010 - Critical (Microsoft)
- Vulnerability Note VU#228569 Microsoft Internet Explorer property memory corrupt (US-CERT)
- ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vuln (Zero Day Initiative)