[SNS Advisory No.67] The Return of the Content-Disposition Vulnerability in IE

From: SecureNet Service(SNS) Spiffy Reviews (snsadv_at_LAC.CO.JP)
Date: 08/21/03

  • Next message: SecureNet Service(SNS) Spiffy Reviews: "[SNS Advisory No.68] Internet Explorer Object Type Buffer Overflow in Double-Byte Character Set Environment"
    Date:         Thu, 21 Aug 2003 13:57:08 +0900
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    ----------------------------------------------------------------------
    SNS Advisory No.67
    The Return of the Content-Disposition Vulnerability in IE

    Problem first discovered on: Wed, 18 Sep 2002
    Published on: Thu, 21 Aug 2003
    ----------------------------------------------------------------------

    Overview:
    ---------
      Microsoft Internet Explorer is prone to a vulnerability that can,
      under several conditions, result in the automatic download and
      parse of a specific tag included with HTML files in the My Computer
      zone without the knowledge of the user.

    Problem Description:
    --------------------
      If specific MIME type is specified in the Content-Type header of
      an HTTP response and if a special string is defined in the Content-
      Disposition header, this string can be automatically downloaded and
      opened within the Temporary Internet Files (TIF) under several
      conditions in Microsoft Internet Explorer. A malicious website
      administrator can induce a user to view a specially crafted web site
      to cause the script to be automatically executed upon viewing the
      malicious contents. Execution of the script can then, disclose the
      path to the TIF directory to the attacker.

      Additionally, if this vulnerability is exploited through a specific
      string in the Content-Disposition header, the OBJECT tag can be
      parsed in the "My Computer" zone. However, if the user has access
      to the malicious Web site, the attacker will be able to execute
      programs on the computer with the user's privileges.

    Tested Version:
    ---------------
      Internet Explorer 6 Service Pack 1 Japanese Edition

    Solution:
    ---------
      Apply an appropriate patch available at:

      Microsoft Security Bulletin MS03-032:
      http://www.microsoft.com/technet/security/bulletin/MS03-032.asp

      Microsoft Security Bulletin MS03-032(Japanese site):
      http://www.microsoft.com/japan/technet/security/bulletin/MS03-032.asp

    Discovered by:
    --------------
      Yuu Arai y.arai@lac.co.jp

    Acknowledgements:
    -----------------

      Thanks to:
      Security Response Team of Microsoft Asia Limited

    Disclaimer:
    -----------
      The information contained in this advisory may be revised without prior
      notice and is provided as it is. Users shall take their own risk when
      taking any actions following reading this advisory. LAC Co., Ltd. shall
      take no responsibility for any problems, loss or damage caused by, or
      by the use of information provided here.

      This advisory can be found at the following URL:
      http://www.lac.co.jp/security/english/snsadv_e/67_e.html

    ------------------------------------------------------------------
    Secure Net Service(SNS) Security Advisory <snsadv@lac.co.jp>
    Computer Security Laboratory, LAC http://www.lac.co.jp/security/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!

    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available. And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to

    http://www.trusecure.com/offer/s0100/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: SecureNet Service(SNS) Spiffy Reviews: "[SNS Advisory No.68] Internet Explorer Object Type Buffer Overflow in Double-Byte Character Set Environment"

    Relevant Pages

    • [SNS Advisory No.67] The Return of the Content-Disposition Vulnerability in IE
      ... The Return of the Content-Disposition Vulnerability in IE ... Microsoft Internet Explorer is prone to a vulnerability that can, ... The information contained in this advisory may be revised without prior ...
      (Bugtraq)
    • Alert: Microsoft Security Bulletin - MS03-032
      ... Customers using Microsoft® Internet Explorer. ... Impact of vulnerability: Two new vulnerabilities, the most serious of which could enable an attacker to run arbitrary code on a user's system if the user either browsed to a hostile Web site or opened a specially crafted HTML-based email message. ... Microsoft Internet Explorer 5.5 ... Summer's Hottest Certification Just Got HOTTER! ...
      (NT-Bugtraq)
    • [NT] CitectSCADA ODBC Service Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... are distributed in over 80 countries through a network of more than 500 ... A vulnerability was found in CitectSCADA that could allow a remote ...
      (Securiteam)
    • Vulnerability Disclosure Formats (was "Re: Funny article")
      ... Common Advisory Interchange Format ... Vendor Status: [was the vendor informed? ... vulnerability a short title, ...
      (Bugtraq)
    • SYMSA-2008-001: Lyris ListManager - Multiple Vulnerabilities
      ... Advisory ID: SYMSA-2008-001 ... mailing lists by modifying client side information sent to the server. ... For details on Symantec's Vulnerability Reporting Policy: ... Symantec Vulnerability Research Advisory Archive: ...
      (Bugtraq)