======================================================================
Secunia Research 09/10/2007
- Internet Explorer File Download Handling Memory Corruption -
======================================================================
Table of Contents
Affected Software....................................................1
Severity.............................................................2
Description of Vulnerability.........................................3
Solution.............................................................4
Time Table...........................................................5
Credits..............................................................6
References...........................................................7
About Secunia........................................................8
Verification.........................................................9
======================================================================
1) Affected Software
* Internet Explorer 5.01
* Internet Explorer 6
* Internet Explorer 7
NOTE: Other versions may also be affected.
======================================================================
2) Severity
Rating: Highly critical
Impact: System compromise
Where: Remote
======================================================================
3) Description of Vulnerability
Secunia Research has discovered a vulnerability in Internet Explorer,
which can be exploited by malicious people to compromise a user's
system.
The vulnerability is caused due to an error in the file download queue
handling when processing multiple concurrent attempts to start a file
download. This can be exploited via a specially crafted web page to
corrupt memory in a way that results in use of an already freed
object.
Successful exploitation allows execution of arbitrary code.
======================================================================
4) Solution
Apply patches (see Microsoft security bulletin for details).
======================================================================
5) Time Table
04/01/2007 - Vendor notified.
04/01/2007 - Vendor response.
09/10/2007 - Public disclosure.
======================================================================
6) Credits
Discovered by Carsten Eiram, Secunia Research.
======================================================================
7) References
The Common Vulnerabilities and Exposures (CVE) project has assigned
CVE-2007-3893 for the vulnerability.
MS07-057 (KB939653):
http://www.microsoft.com/technet/security/Bulletin/MS07-057.mspx
======================================================================
8) About Secunia
Secunia offers vulnerability management solutions to corporate
customers with verified and reliable vulnerability intelligence
relevant to their specific system configuration:
http://corporate.secunia.com/
Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private
individuals, who are interested in or concerned about IT-security.
http://secunia.com/
Secunia believes that it is important to support the community and to
do active vulnerability research in order to aid improving the
security and reliability of software in general:
http://corporate.secunia.com/secunia_research/33/
Secunia regularly hires new skilled team members. Check the URL below
to see currently vacant positions:
http://secunia.com/secunia_vacancies/
Secunia offers a FREE mailing list called Secunia Security Advisories:
http://secunia.com/secunia_security_advisories/
======================================================================
9) Verification
Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2007-31/
Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/
======================================================================
|