Microsoft Internet Explorer 'setRequestHeader()' Multiple Vulnerabilities
BID:28379
Info
Microsoft Internet Explorer 'setRequestHeader()' Multiple Vulnerabilities
| Bugtraq ID: | 28379 |
| Class: | Design Error |
| CVE: |
CVE-2008-1544 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2008 12:00AM |
| Updated: | Jun 18 2008 09:41PM |
| Credit: | Stefano Di Paola is credited with the discovery of these issue. |
| Vulnerable: |
Nortel Networks Contact Center NCC 0 Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Express Nortel Networks Contact Center Administration 0 Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager 9.0 Nortel Networks Centrex IP Client Manager 11.0 Nortel Networks Centrex IP Client Manager 10.0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 5.0.1 SP4 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer 'setRequestHeader()' Multiple Vulnerabilities
Microsoft Internet Explorer is prone to multiple vulnerabilities that allow for referer-spoofing, HTTP-request-splitting, and HTTP-request-smuggling attacks.
A remote attacker may leverage these classes of attacks to poison web caches, steal credentials, evade IDS signatures, and launch cross-site scripting, HTML-injection, and session-hijacking attacks. Other attacks are also possible.
Microsoft Internet Explorer is prone to multiple vulnerabilities that allow for referer-spoofing, HTTP-request-splitting, and HTTP-request-smuggling attacks.
A remote attacker may leverage these classes of attacks to poison web caches, steal credentials, evade IDS signatures, and launch cross-site scripting, HTML-injection, and session-hijacking attacks. Other attacks are also possible.
Exploit / POC
Microsoft Internet Explorer 'setRequestHeader()' Multiple Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to visit a malicious site.
An attacker can exploit these issues by enticing an unsuspecting user to visit a malicious site.
Solution / Fix
Microsoft Internet Explorer 'setRequestHeader()' Multiple Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 5.0.1 SP4
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 (KB950759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=4C47CF8A-8100 -4D43-855A-F225A3492B19&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB950759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=286AADA6-A358 -41F1-B81A-8DE39B9F908A&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 64-bit Itanium Edition (KB9
http://www.microsoft.com/downloads/details.aspx?FamilyId=0262BEB8-1EB5 -4C2D-A50A-0C6C6E0C1F61&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB950759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=6604569A-3DB0 -47E7-BD30-7DFBA8145386&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP (KB950759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=CC325017-3A48 -4475-90E4-0C79A002FCE3&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB950759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C8783CFE-9DA5 -4842-AB3A-1E2BE4FAFC47&displaylang=en
Microsoft Internet Explorer 5.0.1 SP4
-
Microsoft Cumulative Security Update for Internet Explorer 5.01 Service Pack 4 (KB950759)
http://www.microsoft.com/downloads/details.aspx?FamilyId=88990B23-D37F -4D02-A5A3-2EE389ADE53C&displaylang=en
References
Microsoft Internet Explorer 'setRequestHeader()' Multiple Vulnerabilities
References:
References:
- [MSA02240108] IE7 allows overwriting of several headers leading to Http request (Minded Security Research Labs
) - Internet Explorer Homepage (Microsoft)
- [MSA01240108] IE7 Transfer-Encoding: chunked allows Request Splitting/Smuggling. (Minded Security Research Labs
) - #MSA01240108 Microsoft Internet Explorer Transfer-Encoding: chunked allows Reque (Minded Security Labs)
- #MSA02240108 Microsoft Internet Explorer allows overwriting of several headers l (Minded Security Labs)
- ASA-2008-233 MS08-031 Cumulative Security Update for Internet Explorer (950759) (Avaya)
- Centrex IP Client Manager (CICM) response to Microsoft June security bulletin (Nortel Networks)
- Microsoft Security Bulletin MS08-031 (Microsoft)
- Nortel Response to Microsoft Security Bulletin MS08-031 (Nortel Networks)