[NT] Internet Explorer ActiveX Control Heap Overflow (Plugin.ocx, Load)

support_at_securiteam.com
Date: 04/26/03

  • Next message: support_at_securiteam.com: "[NT] DoS Vulnerability Found in VisNetic ActiveDefense"
    To: list@securiteam.com
    Date: 26 Apr 2003 21:43:29 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    In the US?

    Contact Beyond Security at our new California office
    housewarming rates on automated network vulnerability
    scanning. We also welcome ISPs and other resellers!

    Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
    - - - - - - - - -

      Internet Explorer ActiveX Control Heap Overflow (Plugin.ocx, Load)
    ------------------------------------------------------------------------

    SUMMARY

    Internet Explorer is the most popular web browser in use by the internet
    community with a reported 95% user base of internet users. IE suffers from
    a heap based buffer overflow vulnerability that can be exploited via
    e-mail or by viewing a web page.

    DETAILS

    Vulnerable systems:
     * IE 5.01 SP3, 5.5 SP2, 6.0 Gold, 6.0 SP1

    There is an exploitable heap overflow vulnerability in Microsoft's ActiveX
    control, plugin.ocx. By default, plugin.ocx is marked safe for scripting,
    and as such, if an IE user were to visit a malicious web page, the
    overflow could be triggered allowing for a "remote" compromise of the
    user's machine. Alternatively, an attacker could send their target a
    specially crafted e-mail, loaded with an exploit to take advantage of this
    vulnerability. The problem arises by passing an overly long string to the
    Load method of the control.

    Fix Information:
    NGSSoftware alerted Microsoft to this vulnerability on 13th December 2002.
    The patch information is available from
    <http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-015.asp> http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-015.asp.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:nisr@nextgenss.com>
    NGSSoftware Insight Security Research.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: support_at_securiteam.com: "[NT] DoS Vulnerability Found in VisNetic ActiveDefense"

    Relevant Pages

    • [NT] Vulnerability in Microsoft Agent Allows Code Execution (MS07-051)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in Microsoft Agent in the way ... Internet Explorer by setting the kill bit for the control in the registry. ...
      (Securiteam)
    • [NT] Vulnerability in OLE Automation Allows Code Execution
      ... Get your security news from a reliable source. ... This critical security update resolves a privately reported vulnerability. ... compromised Web sites and advertisement servers could contain specially ... mode sets the security level for the Internet zone to High. ...
      (Securiteam)
    • [NT] Vulnerability in the Indexing Service Allows Remote Code Execution (MS05-003)
      ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in the Indexing Service ... connected to the Internet have a minimal number of ports exposed. ...
      (Securiteam)
    • [NT] Vulnerability in Windows Shell Allows Remote Code Execution (MS05-008)
      ... Get your security news from a reliable source. ... A privilege elevation vulnerability exists in Windows because of the way ... MS03-040 or a later Cumulative Security Update for Internet Explorer. ... Note Setting the level to High may cause some Web sites to work ...
      (Securiteam)
    • [NT] Vulnerability in Windows Explorer Allows Execution (MS06-057)
      ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in Windows Shell due to ... Prevent the WebViewFolderIcon ActiveX object from running in Internet ... Web sites that use the WebViewFolderIcon ActiveX ...
      (Securiteam)