Secunia Logo  


Secunia PSI WorldMap
 
Internet Explorer Data Binding Memory Corruption Vulnerability
Secunia Advisory: SA33089
Release Date: 2008-12-10
Last Update: 2009-01-27
Popularity: 81,879 views

Critical:
Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 6.x
Microsoft Internet Explorer 7.x

Binary Analysis: BA633 :: Available for 1 Credit

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply patches.

Windows 2000 SP4 and Internet Explorer 5.01 SP4:
http://www.microsoft.com/downloads/de...=d3e18732-47f1-40ce-999c-d1fd283bf138

Windows 2000 SP4 and Internet Explorer 6 SP1:
http://www.microsoft.com/downloads/de...=124c14b6-9323-4f6f-902b-727aa56444bc

Windows XP SP2/SP3 and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=1d83e0af-46fa-4bfc-ba57-635435a7ef2d

Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=a585cb73-2c1a-4fa8-862a-ad6aeaeaf2f8

Windows Server 2003 SP1/SP2 and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=d81e9cf9-ce0c-463a-a359-49a348cb89ae

Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=015df302-d79f-43a1-b5c5-32ac04de0510

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Internet Explorer 6:
http://www.microsoft.com/downloads/de...=18016305-7f72-47f6-ab4c-94282289bf5f

Windows XP SP2/SP3 and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=0190a289-164e-41a7-8c01-fa1aaed3f531

Windows XP Professional x64 Edition (optionally with SP2) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=9ba71e23-8cef-4399-b215-983b0dcf5cb5

Windows Server 2003 SP1/SP2 and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=388847ec-817e-45cf-8fa7-32c7e1f57f80

Windows Server 2003 x64 Edition (optionally with SP2) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=2ae17caf-6204-470e-8480-380d3d505657

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=97d6c093-f68d-4ddf-8e3c-f29662a1940f

Windows Vista (optionally with SP1) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=7887111d-4fac-4823-bdd2-a18d9468fdf0

Windows Vista x64 Edition (optionally with SP1) and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=69979d92-8d45-47fe-ac4c-c2f1f23cf1fb

Windows Server 2008 for 32-bit Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=5552e564-dd1c-4e2a-9a42-6317522c884d

Windows Server 2008 for x64-based Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=889c6eb1-7d1f-4e60-b637-535cb6e4e443

Windows Server 2008 for Itanium-based Systems and Internet Explorer 7:
http://www.microsoft.com/downloads/de...=06cb502a-6818-4599-aa24-6eddb83e4b84

Provided and/or discovered by:
Reported as a 0-day.

Additional information provided by Secunia Research.

Changelog:
2008-12-11: Added additional information provided by Microsoft.
2008-12-11: Updated the "Other References" section. Added more information and "Microsoft Internet Explorer 6.x" to the list of affected products based on additional research performed by Secunia Research.
2008-12-12: Added "Microsoft Internet Explorer 5.01" to the list of affected products. Updated "Solution" section with workaround information.
2008-12-17: Updated "Solution" section. Added link to Microsoft security bulletin.
2009-01-27: Added link to Secunia blog posting.

Original Advisory:
MS08-078 (KB960714):
http://www.microsoft.com/technet/security/Bulletin/MS08-078.mspx

KnownSec:
http://www.scanw.com/blog/archives/303

Microsoft:
http://www.microsoft.com/technet/security/advisory/961051.mspx

Other References:
McAfee Avert Labs:
http://www.avertlabs.com/research/blo...ed-drive-by-exploit-found-on-the-web/

US-CERT VU#493881:
http://www.kb.cert.org/vuls/id/493881

Secunia Blog - "Internet Explorer Data Binding 0-Day Clarifications":
http://secunia.com/blog/38/

Extended Solution:
The "Extended Solution" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Internet Explorer Layout Handling Memory Corruption Vulnerability // 218 views
2. Debian update for gforge // 67 views
3. VMware Products Update for Multiple Packages // 66 views
4. VMware ESX and vMA Update for Multiple Packages // 63 views
5. VMware ESXi update for ntp // 61 views
6. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 46 views
7. PHP Multiple Vulnerabilities // 42 views
8. MySQL Denial of Service and Client Certificate Verification Vulnerabilities // 42 views
9. NaSMail Cross-Site Scripting and Request Forgery Vulnerabilities // 38 views
10. Sun Java JDK / JRE Multiple Vulnerabilities // 31 views