|
 |
|
Internet Explorer flere sårbarheder
|
|
|
|
|
Secunia Advisory:
|
SA28036
|
|
|
Udsendt:
|
2007-12-11
|
|
Sidste Opdt.:
|
2007-12-19
|
|
|
Kritisk:
|

Ekstremt kritisk
|
|
Betydning:
|
Systemadgang
|
|
Hvor:
|
Fra Internet
|
|
Løsning Status:
|
Producent Patch
|
|
| Software: | Microsoft Internet Explorer 5.01 Microsoft Internet Explorer 6.x Microsoft Internet Explorer 7.x
|
| | CVE reference: | CVE-2007-3902 (Secunia mirror) CVE-2007-3903 (Secunia mirror) CVE-2007-5344 (Secunia mirror) CVE-2007-5347 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Beskrivelse: Der er rapporteret nogle sårbarheder i Internet Explorer, som kan udnyttes af ondsindede personer til at kompromittere en brugers system.
1) En "use-after-free" fejl i mshtml.dll under håndteringen af "setExpression()" metode-kald kan udnyttes til at dereferere tidligere frigjort hukommelse via en ondsindet webside indeholdende specielt udformet scriptkode.
2) En fejl under håndteringen af "cloneNode()" og "nodeValue()" metoderne kan udnyttes til at korrumpere hukommelsen.
3) En fejl under håndteringen af dokument-objekter, der er oprettet, modificeret, slettet og derefter tilgås, kan udnyttes til at korrumpere hukommelsen.
4) En fejl ved visning af websider indeholdende visse metode-kald til HTML-objekter kan udnyttes til at korrumpere hukommelsen.
NOTE: Det rapporteres, at denne sårbarhed udnyttes aktivt på nuværende tidspunkt.
Succesfuld udnyttelse af sårbarhederne kan muliggøre eksekvering af vilkårlig kode, når en bruger f.eks. besøger et ondsindet website.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Løsning: Installér patches.
Windows 2000 SP4 with Internet Explorer 5.01 SP4:
http://www.microsoft.com/downloads/de...=B3BD16EA-5D69-4AE3-84B3-AB773052CEEB
Windows 2000 SP4 with Internet Explorer 6 SP1:
http://www.microsoft.com/downloads/de...=BC8EDF05-262A-4D1D-B196-4FC1A844970C
Windows XP SP2 with Internet Explorer 6:
http://www.microsoft.com/downloads/de...=6E4EBAFC-34C3-4DC7-B712-152C611D3F0A
Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=F5A5AF23-30FB-4E47-94BD-3B05B55C92F2
Windows Server 2003 SP1/SP2 with Internet Explorer 6:
http://www.microsoft.com/downloads/de...=BF466060-A585-4C2E-A48D-70E080C3BBE7
Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=074697F2-18C8-4521-BBF7-1D0E7395D27D
Windows Server 2003 with SP1/SP2 for Itanium-based systems and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=B3F390A6-0361-4553-B627-5E7AD6BF5055
Windows XP SP2 with Internet Explorer 7:
http://www.microsoft.com/downloads/de...=B15A6506-02DD-43C2-AEF4-E10C1C76EE97
Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=C092A6BB-8E62-4D90-BDB1-5F3A15968F75
Windows Server 2003 SP1/SP2 with Internet Explorer 7:
http://www.microsoft.com/downloads/de...=34759C10-16A5-42A2-974D-9D532FB5A0A7
Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=7DCCCE5A-7562-448B-A345-CF1CC758E35C
Windows Server 2003 with SP1/SP2 for Itanium-based systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=8414F3FB-216A-4D46-B590-4C1F304DFF91
Windows Vista with Internet Explorer 7:
http://www.microsoft.com/downloads/de...=26D303DA-BB2E-4555-96F1-BECB0E277341
Windows Vista x64 Edition with Internet Explorer 7:
http://www.microsoft.com/downloads/de...=C5E88E0B-A4C2-4690-91D9-326800030A16
Rapporteret af / Kredit: 1) Rapporteret af en anonym person via ZDI.
Producenten krediterer yderligere Peter Vreugdenhil via iDefense VCP.
2) Sam Thomas via Zero Day Initiative.
3) Peter Vreugdenhil via Zero Day Initiative.
4) Rapporteret som en 0-day.
Forløb: 12-12-2007: Tilføjede yderligere information fra ZDI.
13-12-2007: Tilføjede yderligere information fra iDefense.
19-12-2007: Opdaterede udvidet løsning.
Original Advisory: MS07-069 (KB942615):
http://www.microsoft.com/technet/security/Bulletin/MS07-069.mspx
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-07-073.html
http://www.zerodayinitiative.com/advisories/ZDI-07-074.html
http://www.zerodayinitiative.com/advisories/ZDI-07-075.html
iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=631
Dybdegående Løsning: The "Dybdegående Løsning" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
134 Relaterede Secunia Advisories, displaying 10
|
|
|
1. Microsoft "Web Proxy Auto-Discovery" feature sikkerhedsproblem
|
|
2. Internet Explorer uspecificeret addressbar-spoofing
|
|
3. Internet Explorer "OnKeyDown" fokus-svaghed
|
|
4. Microsoft Internet Explorer afsløring af FTP login-oplysninger
|
|
5. Microsoft Internet Explorer flere sårbarheder
|
|
6. Microsoft Windows Vector Markup Language buffer overflow
|
|
7. Internet Explorer "document.open()" adressebar-spoofing
|
|
8. Microsoft Internet Explorer 7 HTTP Basic Authentication IDN-spoofing
|
|
9. Internet Explorer flere sårbarheder
|
|
10. Internet Explorer side-loading race condition og URL-spoofing
|
Vis alle relaterede advisories
|
|
|
Send Feedback to Secunia
|
|
Hvis du har ny information angående dette Secunia advisory eller et produkt i vores database, så send det venligst til os. Du kan sende det til os enten ved at bruge vores web formular eller ved at sende det til vuln@secunia.com.
Ideer, foreslag og andet feedback er også meget velkommen.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|