Re: Compromising pictures of Microsoft Internet Explorer!

From: Michal Zalewski (lcamtuf_at_dione.ids.pl)
Date: 08/11/05

  • Next message: Martin Pitt: "[USN-164-1] netpbm vulnerability"
    Date: Thu, 11 Aug 2005 13:14:46 +0200 (CEST)
    To: bugtraq@securityfocus.com
    
    
    

    > This experiment resulted in identifying a potential remote code
    > execution path in Microsoft Internet Explorer, plus some other bugs, and
    > should be a good starting point for further testing of other browsers or
    > similar programs.

    Just for the reference, this is confirmed to be fixed by the most recent
    (and long overdue) cummulative update for MSIE (a part of MS05-038):

    JPEG Image Rendering Memory Corruption Vulnerability - CAN-2005-1988

       A remote code execution vulnerability exists in Internet Explorer
       because of the way that it handles JPEG images. An attacker could
       exploit the vulnerability by constructing a malicious JPEG image that
       could potentially allow remote code execution if a user visited a
       malicious Web site or viewed a malicious e-mail message. An attacker
       who successfully exploited this vulnerability could take complete
       control of an affected system.

    Thought I'd clarify, because CVE seems to carry original references with
    one candidate entry (CAN-2005-2308), and Microsoft's patch with no prior
    references in another (CAN-2005-1988) - so there might be some confusion
    as to what was fixed and why. CERT and Securityfocus both include proper
    data, though.

    Cheers,
    /mz
    http://lcamtuf.coredump.cx/silence/

    
    



  • Next message: Martin Pitt: "[USN-164-1] netpbm vulnerability"

    Relevant Pages

    • [NT] Cumulative Security Update for Internet Explorer (MS08-058)
      ... Get your security news from a reliable source. ... Cumulative Security Update for Internet Explorer ... one publicly disclosed vulnerability. ... A remote code execution or information disclosure vulnerability exists in ...
      (Securiteam)
    • [Full-disclosure] Re: Compromising pictures of Microsoft Internet Explorer!
      ... JPEG Image Rendering Memory Corruption Vulnerability - CAN-2005-1988 ... A remote code execution vulnerability exists in Internet Explorer ...
      (Full-Disclosure)
    • [NT] Cumulative Security Update for Internet Explorer (MS08-010)
      ... Get your security news from a reliable source. ... Cumulative Security Update for Internet Explorer ... A remote code execution vulnerability exists in the way Internet Explorer ...
      (Securiteam)
    • SecurityFocus Microsoft Newsletter #445
      ... MICROSOFT VULNERABILITY SUMMARY ... Apple Safari CoreGraphics TrueType Font Handling Remote Code Execution Vulnerability ... Microsoft Windows Argument Validation Local Privilege Escalation Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #313
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Class Package Export Tool Clspack.exe Local Buffer Overflow Vulnerability ... Microsoft PowerPoint Unspecified Remote Unspecified Code Execution Vulnerability ... Microsoft Office Malformed Record Remote Code Execution Vulnerability ...
      (Focus-Microsoft)

  • Quantcast