Outpost 個人防火牆 - Cumulative Security Update for Internet Explorer Browser
Agnitum Security Advisories
ASA-06-0508-4: Cumulative Security Update for Internet Explorer Browser
Vulnerability summary:
|
Severity rating:
|
Critical
|
|
|
Date Published:
|
August 9, 2005
|
|
|
Software Vendor:
|
Microsoft
|
|
|
Affected Software:
|
Internet Explorer (iexplore.exe)
|
|
|
Affected OS:
|
Windows 2000 (all), Windows XP (all), Windows Server 2003 (all), Windows 98 (incl. SE), Windows Millennium Edition (ME)
|
|
|
Unaffected with:
|
-
|
|
|
Vulnerability class:
|
Remote Code Execution
|
|
|
Status:
|
Fixed
|
Vulnerability details:
Tech brief:
Three critical vulnerabilities all affecting Microsoft Internet Explorer web browser are resolved with the patch. Below are details on separate vulnerabilities.
- JPEG Image Rendering Memory Corruption Vulnerability
A remote code execution vulnerability exists in Internet Explorer because of the way that it handles JPEG images. An attacker could exploit the vulnerability by constructing a malicious JPEG image that could potentially allow remote code execution if a user visited a malicious Web site or viewed a malicious e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system and gain the same user rights as the local user.
An attacker could exploit this vulnerability by creating a malicious Web page or an HTML e-mail message and then persuading the user to visit the page or to view the HTML e-mail message. If the user visited the page or viewed the e-mail message, the attacker could access information from other Web sites, could access local files in predetermined locations on the system, or could cause malicious code to run in the security context of the locally logged on user. An attacker could also try to compromise a Web site and have it display malicious content.
- Web Folder Behaviors Cross-Domain Vulnerability
A cross-domain vulnerability exists in Internet Explorer that could allow information disclosure or remote code execution on an affected system. An attacker could exploit the vulnerability by constructing a malicious Web page and persuade users to access it. The malicious Web page could potentially allow remote code execution if it is viewed by a user. An attacker who successfully exploited this vulnerability could take complete control of an affected system. However, significant user interaction and social engineering is required to exploit this vulnerability.
- COM Object Instantiation Memory Corruption Vulnerability
When Internet Explorer tries to instantiate certain COM objects as ActiveX controls, the COM Objects may corrupt system memory in such a way that an attacker could execute arbitrary code. A remote code execution vulnerability exists in the way Internet Explorer instantiates COM Objects that are not intended to be used in Internet Explorer. An attacker could exploit the vulnerability by constructing a malicious Web page that could potentially allow remote code execution if a user visited the malicious Web site. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Vendor reference information:
Vendor details pertaining to the problem are available here:
http://www.microsoft.com/technet/security/Bulletin/MS05-038.mspx
General Mitigating Recommendations:
Install latest vendor patches available at http://windowsupdate.microsoft.com.
Use plain text in viewing an email instead of rich and multimedia-supported format.
How the Outpost Firewall PRO protects you:
With Outpost's Active Content plug-in you can disable the execution of ActiveX controls and plug-ins on all web sites except the ones you trust. Thus you would protect your system from the most commonly exploited avenue to compromise IE security.
Disclaimer:
Information in the present advisory is believed to be accurate as to the time of publishing based on currently available information. Use of the information signifies acceptance for use in an AS IS condition. There are no warranties with regard to this information. Agnitum Ltd. doesn't accept any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.
關於Version 2 Limited
Version 2 Limited 是亞洲其中一間最有活力的IT公司,公司發展及代理各種不同的互聯網及IP-Based 網絡IT產品,當中包括通訊系統、保安、網絡及媒體產品。透過公司龐大的網絡、銷售點、分銷商及合作顆伴,Version 2 Limited 便可提供廣被市場讚賞的產品及服務。Version 2 Limited 客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的客戶。
如對產品有興趣,可瀏覽以下網址:
http://www.version-2.com/op
http://www.version-2.com/nod32op
![]()

台灣
RSS

