(Vendor Issues Revised Fix) Microsoft Internet Explorer Integer Overflow in Processing Bitmap Files Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1010826
|
|
SecurityTracker URL: http://securitytracker.com/id?1010826
|
|
CVE Reference: CAN-2004-0566
(Links to External Site)
|
Updated: Aug 1 2004
|
Original Entry Date: Jul 30 2004
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 5.01, 5.5, 6
|
Description: A vulnerability was reported in Microsoft Internet Explorer (IE) version 5. A remote user can execute arbitrary code on the target system.
It is reported that a remote user can create a specially crafted bitmap file that, when loaded by IE, will trigger an integer overflow
and execute arbitrary code.
The author states that this flaw was found by reviewing the recently leaked Microsoft Windows source
code. The flaw reportedly resides in 'win2k/private/inet/mshtml/src/site/download/imgbmp.cxx'.
The report indicates that IE
5 is affected but that IE 6 is not affected, however, Microsoft has indicated that version 6 is also vulnerable.
A demonstration
exploit is provided in the Source Message [it is Base64 encoded].
|
Impact: A remote user can cause arbitrary code to be executed on the target user's computer when the target user's browser loads a specially crafted bitmap file. The code will run with the privileges of the target user.
|
Solution: On July 30, 2004, Microsoft issued fixes as part of a cumulative update (MS04-025). The applicable URLs are listed below.
On
August 1, 2004, Microsoft re-issued security bulletin MS04-025 to warn Windows XP customers using Windows Update version 5 that
they need to reapply the fix because the original Windows Update version 5 files did not contain the proper fixes. To verify if
you are using Windows Update version 5, Microsoft indicates that you can look for the 'Express Install' arrow on the Windows Update
home page and if you see the 'Express Install' arrow on the home page, then you have version 5 installed. If you are affected and
are using the automatic update feature, the new fixes will be applied automatically, the advisory said. If you are affected and
are using the manual update feature, then you need to reapply the update.
The following fixes are available.
Internet Explorer
5.01 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=507E71EF-076B-43C4-8028-E91FCFAB252B&displaylang=en
Internet
Explorer 5.01 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7AA6F31D-7350-43F8-B72E-ED9D62577A60&displaylang=en
Internet
Explorer 5.01 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=862E6914-821A-4C51-985B-C3958FAD3D4C&displaylang=en
Internet
Explorer 5.5 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=E458480C-93F6-454A-A663-FC187C18CD9B&displaylang=en
Internet
Explorer 6:
http://www.microsoft.com/downloads/details.aspx?FamilyId=4C2F8A40-1B88-4F93-98B1-1619DCFD7273&displaylang=en
Internet
Explorer 6 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=06F49985-F19F-4B50-A75F-7636D8BEE576&displaylang=en
Internet
Explorer 6 Service Pack 1 (64-Bit Edition):
http://www.microsoft.com/downloads/details.aspx?FamilyId=FCDA580D-9E3B-4B44-BD65-C8D37A0DD62D&displaylang=en
Internet
Explorer 6 for Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=D86262D9-C66A-4608-8DBE-2492B4AFBC3B&displaylang=en
Internet
Explorer 6 for Windows Server 2003 (64-Bit Edition):
http://www.microsoft.com/downloads/details.aspx?FamilyId=1AA8F5A9-71D3-48F7-BB32-F8A4D36C5FB9&displaylang=en
Mi
crosoft reports that IE 6 SP1 and IE 6 for Windows Server 2003 are not affected by this vulnerability.
Microsoft notes that this
update does not include "hotfixes" for Internet Explorer provided since the release of MS04-004. If you have received hotfixes,
see the vendor's advisory for more information:
http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms04-025.mspx (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 30 Jul 2004 14:14:17 -0400
Subject: http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx
|
http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx
> Microsoft Security Bulletin MS04-025
> Cumulative Security Update for Internet Explorer (867801)
> Impact of Vulnerability: Remote Code Execution
> Maximum Severity Rating: Critical
> Security Update Replacement: This update replaces the one that is provided in Microsoft
> Security Bulletin MS04-004, which is itself a cumulative update.
Navigation Method Cross-Domain Vulnerability - CAN-2004-0549
Malformed BMP File Buffer Overrun Vulnerability - CAN-2004-0566
Malformed GIF File Double Free Vulnerability - CAN-2003-1048
Microsoft has issued the following fixes:
Internet Explorer 5.01 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=507E71EF-076B-43C4-8028-E91FCFAB252B&dis playlang=en
Internet Explorer 5.01 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7AA6F31D-7350-43F8-B72E-ED9D62577A60&dis playlang=en
Internet Explorer 5.01 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=862E6914-821A-4C51-985B-C3958FAD3D4C&dis playlang=en
Internet Explorer 5.5 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=E458480C-93F6-454A-A663-FC187C18CD9B&dis playlang=en
Internet Explorer 6:
http://www.microsoft.com/downloads/details.aspx?FamilyId=4C2F8A40-1B88-4F93-98B1-1619DCFD7273&dis playlang=en
Internet Explorer 6 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=06F49985-F19F-4B50-A75F-7636D8BEE576&dis playlang=en
Internet Explorer 6 Service Pack 1 (64-Bit Edition):
http://www.microsoft.com/downloads/details.aspx?FamilyId=FCDA580D-9E3B-4B44-BD65-C8D37A0DD62D&dis playlang=en
Internet Explorer 6 for Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=D86262D9-C66A-4608-8DBE-2492B4AFBC3B&dis playlang=en
Internet Explorer 6 for Windows Server 2003 (64-Bit Edition):
http://www.microsoft.com/downloads/details.aspx?FamilyId=1AA8F5A9-71D3-48F7-BB32-F8A4D36C5FB9&dis playlang=en
|
|