Secunia Logo  


Secunia PSI WorldMap
 
Internet Explorer Data Binding Memory Corruption Vulnerability
Secunia Advisory: SA33089
Release Date: 2008-12-10
Last Update: 2009-01-27
Popularity: 81,636 views

Critical:
Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 6.x
Microsoft Internet Explorer 7.x

Binary Analysis: BA633 :: Available for 1 Credit

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply patches.

Windows 2000 SP4 and Internet Explorer 5.01 SP4:
http://www.microsoft.com/downloads/de...=d3e18732-47f1-40ce-999c-d1fd283bf138

Windows 2000 SP4 and Internet Explorer 6 SP1:
http://www.microsoft.com/downloads/de...=124c14b6-9323-4f6f-902b-727aa56444bc

Windows XP SP2/SP3 and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=1d83e0af-46fa-4bfc-ba57-635435a7ef2d

Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=a585cb73-2c1a-4fa8-862a-ad6aeaeaf2f8

Windows Server 2003 SP1/SP2 and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=d81e9cf9-ce0c-463a-a359-49a348cb89ae

Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=015df302-d79f-43a1-b5c5-32ac04de0510

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=18016305-7f72-47f6-ab4c-94282289bf5f

Windows XP SP2/SP3 and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=0190a289-164e-41a7-8c01-fa1aaed3f531

Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=9ba71e23-8cef-4399-b215-983b0dcf5cb5

Windows Server 2003 SP1/SP2 and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=388847ec-817e-45cf-8fa7-32c7e1f57f80

Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=2ae17caf-6204-470e-8480-380d3d505657

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=97d6c093-f68d-4ddf-8e3c-f29662a1940f

Windows Vista (optionally with SP1) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=7887111d-4fac-4823-bdd2-a18d9468fdf0

Windows Vista x64 Edition (optionally with SP1) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=69979d92-8d45-47fe-ac4c-c2f1f23cf1fb

Windows Server 2008 for 32-bit Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=5552e564-dd1c-4e2a-9a42-6317522c884d

Windows Server 2008 for x64-based Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=889c6eb1-7d1f-4e60-b637-535cb6e4e443

Windows Server 2008 for Itanium-based Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=06cb502a-6818-4599-aa24-6eddb83e4b84

Provided and/or discovered by:
Reported as a 0-day.

Additional information provided by Secunia Research.

Changelog:
2008-12-11: Added additional information provided by Microsoft.
2008-12-11: Updated the "Other References" section. Added more information and "Microsoft Internet Explorer 6.x" to the list of affected products based on additional research performed by Secunia Research.
2008-12-12: Added "Microsoft Internet Explorer 5.01" to the list of affected products. Updated "Solution" section with workaround information.
2008-12-17: Updated "Solution" section. Added link to Microsoft security bulletin.
2009-01-27: Added link to Secunia blog posting.

Original Advisory:
MS08-078 (KB960714):
http://www.microsoft.com/technet/security/Bulletin/MS08-078.mspx

KnownSec:
http://www.scanw.com/blog/archives/303

Microsoft:
http://www.microsoft.com/technet/security/advisory/961051.mspx

Other References:
McAfee Avert Labs:
http://www.avertlabs.com/research/blo...ed-drive-by-exploit-found-on-the-web/

US-CERT VU#493881:
http://www.kb.cert.org/vuls/id/493881

Secunia Blog - "Internet Explorer Data Binding 0-Day Clarifications":
http://secunia.com/blog/38/

Extended Solution:
The "Extended Solution" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Microsoft Windows Win32k Kernel-Mode Driver Multiple Vulnerabilities // 129 views
2. Internet Explorer Three Vulnerabilities // 74 views
3. IBM BladeCenter Advanced Management Module Unspecified Vulnerabilities // 68 views
4. Sun Java JDK / JRE Multiple Vulnerabilities // 67 views
5. Windows Web Services on Devices API Memory Corruption Vulnerability // 61 views
6. Microsoft Excel Multiple Vulnerabilities // 59 views
7. Citrix Secure Gateway TLS Session Renegotiation Plaintext Injection // 56 views
8. Super Serious Stats "uid" SQL Injection Vulnerability // 53 views
9. Deliantra Server Two Buffer Overflow Vulnerabilities // 52 views
10. Microsoft Office Word File Information Block Parsing Buffer Overflow // 51 views