Microsoft Internet Explorer Uninitialized Object Remote Memory Corruption Vulnerability
BID:31617
Info
Microsoft Internet Explorer Uninitialized Object Remote Memory Corruption Vulnerability
| Bugtraq ID: | 31617 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-3475 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2008 12:00AM |
| Updated: | Oct 24 2008 03:36PM |
| Credit: | Ivan Fratric working with TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Express Nortel Networks Contact Center Administration 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Uninitialized Object Remote Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Internet Explorer Uninitialized Object Remote Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Internet Explorer Uninitialized Object Remote Memory Corruption Vulnerability
Solution:
Microsoft released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
Microsoft Internet Explorer 6.0
Solution:
Microsoft released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Internet Explorer 6.0 SP1
-
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=02390258-08E9 -4B75-960D-BE081B749558&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=AE8D22D5-20AA -471D-A423-F54C9D75FEBE&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=07FC88C4-2571 -4A4D-B573-AE576798AB4C&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=A7F0F47B-B1EE -4516-9FBF-BF8E579963D0&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=234C05FB-988B -4E02-AAB6-BB23E447DF3D&displaylang=en
Microsoft Internet Explorer 6.0
-
Microsoft Cumulative Security Update for Internet Explorer 6 SP1 (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=02390258-08E9 -4B75-960D-BE081B749558&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=AE8D22D5-20AA -471D-A423-F54C9D75FEBE&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=07FC88C4-2571 -4A4D-B573-AE576798AB4C&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=A7F0F47B-B1EE -4516-9FBF-BF8E579963D0&displaylang=en -
Microsoft Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB956390)
http://www.microsoft.com/downloads/details.aspx?familyid=234C05FB-988B -4E02-AAB6-BB23E447DF3D&displaylang=en
References
Microsoft Internet Explorer Uninitialized Object Remote Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Internet Explorer 6 componentFromPoint() remote memory disclosure and remote cod ("Ivan Fratric"
) - ZDI-08-069: Microsoft Internet Explorer componentFromPoint Memory Corruption Vu ([email protected])
- Microsoft Security Bulletin MS08-058 (Microsoft )
- Nortel Response to Microsoft Security Bulletin MS08-058 (Nortel Networks)
- ZDI-08-069: Microsoft Internet Explorer componentFromPoint Memory Corruption Vul (Zero Day Initiative)