Internet Explorer Plugin.ocx heap overflow (#NISR24042003)

From: NGSSoftware Insight Security Research (nisr@NEXTGENSS.COM)
Date: 04/24/03

  • Next message: Network Intelligence India Pvt. Ltd.: "NII Advisory - Path Disclosure in Cold Fusion MX Server"
    Date:         Thu, 24 Apr 2003 17:14:59 +0100
    From: NGSSoftware Insight Security Research <nisr@NEXTGENSS.COM>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    NGSSoftware Insight Security Research Advisory

    Name: Internet Explorer ActiveX Control Heap Overflow
    Systems Affected: IE 5.01 SP3, 5.5 SP2, 6.0 Gold, 6.0 SP1
    Severity: Critical Risk
    Category: Heap Overflow
    Vendor URL: http://www.microsoft.com
    Author: Mark Litchfield (mark@ngssoftware.com)
    Date: 24th April 2003
    Advisory number: #NISR24042003

    Description
    ***********
    Internet Explorer is the most popular web browser in use by the internet
    community with a reported 95% user base of internet users. IE suffers from a
    heap based buffer overflow vulnerability that can be exploited via e-mail or
    by viewing a web page.

    Details
    *******
    There is an exploitable heap overflow vulnerability in Microsoft's ActiveX
    control, Plugin.ocx. By default, plugin.ocx is marked safe for scripting,
    and as such, if an IE user were to visit a malicious web page, the overflow
    could be triggered allowing for a "remote" compromise of the user's machine.
    Alternatively, an attacker could send their target a specially crafted
    e-mail, loaded with an exploit to take advantage of this vulnerability. The
    problem arises by passing an overly long string to the Load method of the
    control.

    Fix Information
    ***************
    NGSSoftware alerted Microsoft to this vulnerability on 13th December 2002.
    The patch information is available from
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
    bulletin/MS03-015.asp

    Further Information
    *******************
    For further information about the scope and effects of buffer overflows,
    please see

    http://www.ngssoftware.com/papers/non-stack-bo-windows.pdf
    http://www.ngssoftware.com/papers/ntbufferoverflow.html
    http://www.ngssoftware.com/papers/bufferoverflowpaper.rtf
    http://www.ngssoftware.com/papers/unicodebo.pdf

    About NGSSoftware
    *****************
    NGSSoftware design, research and develop intelligent, advanced application
    security assessment scanners. Based in the United Kingdom, NGSSoftware have
    offices in the South of London and the East Coast of Scotland. NGSSoftware's
    sister company NGSConsulting, offers best of breed security consulting
    services, specialising in application, host and network security
    assessments.

    http://www.ngssoftware.com/
    http://www.ngsconsulting.com/

    Telephone +44 208 401 0070
    Fax +44 208 401 0076

    enquiries@ngssoftware.com

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Have you discovered a security vulnerability related to Windows or a
    commercial product which runs on Windows?

    Need assistance crafting the format or translating your advisory to English?

    Need to verify it, or having problems contacting the Vendor?

    Contact mailto:Advisories@NTBugtraq.com

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: Network Intelligence India Pvt. Ltd.: "NII Advisory - Path Disclosure in Cold Fusion MX Server"

    Relevant Pages

    • Internet Explorer Plugin.ocx heap overflow (#NISR24042003)
      ... Internet Explorer is the most popular web browser in use by the internet ... heap based buffer overflow vulnerability that can be exploited via e-mail or ... There is an exploitable heap overflow vulnerability in Microsoft's ActiveX ... security assessment scanners. ...
      (Bugtraq)
    • [NT] Internet Explorer ActiveX Control Heap Overflow (Plugin.ocx, Load)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Internet Explorer is the most popular web browser in use by the internet ... a heap based buffer overflow vulnerability that can be exploited via ... There is an exploitable heap overflow vulnerability in Microsoft's ActiveX ...
      (Securiteam)
    • Risks Digest 26.65
      ... ACM FORUM ON RISKS TO THE PUBLIC IN COMPUTERS AND RELATED SYSTEMS ... Internet Amorality, and Cutting Thailand Off From the Internet ... "Face Unlock feature in Galaxy Nexus poses security risk" (Matt Hamblen via ... Facebook Settles With F.T.C. Over Deception Charges ...
      (comp.risks)
    • Risks Digest 26.94
      ... ACM FORUM ON RISKS TO THE PUBLIC IN COMPUTERS AND RELATED SYSTEMS ... Olympics security poster 'gibberish' to Arabic speakers ... Apple removes security app from the App Store ... Who Really Invented the Internet? ...
      (comp.risks)
    • [NT] Vulnerability in Microsoft Data Access Components Allows Code Execution (MS07-009)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... this vulnerability by preventing Active Scripting and ActiveX controls ... mode sets the security level for the Internet zone to High. ...
      (Securiteam)