SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Browser)  >   Microsoft Internet Explorer Vendors:   Microsoft
(Vendor Issues Revised Fix) Microsoft Internet Explorer Integer Overflow in Processing Bitmap Files Lets Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1010826
SecurityTracker URL:  http://securitytracker.com/id/1010826
CVE Reference:   CAN-2004-0566   (Links to External Site)
Updated:  Aug 1 2004
Original Entry Date:  Jul 30 2004
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 5.01, 5.5, 6
Description:   A vulnerability was reported in Microsoft Internet Explorer (IE) version 5. A remote user can execute arbitrary code on the target system.

It is reported that a remote user can create a specially crafted bitmap file that, when loaded by IE, will trigger an integer overflow and execute arbitrary code.

The author states that this flaw was found by reviewing the recently leaked Microsoft Windows source code. The flaw reportedly resides in 'win2k/private/inet/mshtml/src/site/download/imgbmp.cxx'.

The report indicates that IE 5 is affected but that IE 6 is not affected, however, Microsoft has indicated that version 6 is also vulnerable.

A demonstration exploit is provided in the Source Message [it is Base64 encoded].

Impact:   A remote user can cause arbitrary code to be executed on the target user's computer when the target user's browser loads a specially crafted bitmap file. The code will run with the privileges of the target user.
Solution:   On July 30, 2004, Microsoft issued fixes as part of a cumulative update (MS04-025). The applicable URLs are listed below.

On August 1, 2004, Microsoft re-issued security bulletin MS04-025 to warn Windows XP customers using Windows Update version 5 that they need to reapply the fix because the original Windows Update version 5 files did not contain the proper fixes. To verify if you are using Windows Update version 5, Microsoft indicates that you can look for the 'Express Install' arrow on the Windows Update home page and if you see the 'Express Install' arrow on the home page, then you have version 5 installed. If you are affected and are using the automatic update feature, the new fixes will be applied automatically, the advisory said. If you are affected and are using the manual update feature, then you need to reapply the update.

The following fixes are available.

Internet Explorer 5.01 Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=507E71EF-076B-43C4-8028-E91FCFAB252B&displaylang=en


Internet Explorer 5.01 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AA6F31D-7350-43F8-B72E-ED9D62577A60&displaylang=en


Internet Explorer 5.01 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=862E6914-821A-4C51-985B-C3958FAD3D4C&displaylang=en


Internet Explorer 5.5 Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=E458480C-93F6-454A-A663-FC187C18CD9B&displaylang=en


Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=4C2F8A40-1B88-4F93-98B1-1619DCFD7273&displaylang=en


Internet Explorer 6 Service Pack 1:

http://www.microsoft.com/downloads/details.aspx?FamilyId=06F49985-F19F-4B50-A75F-7636D8BEE576&displaylang=en


Internet Explorer 6 Service Pack 1 (64-Bit Edition):

http://www.microsoft.com/downloads/details.aspx?FamilyId=FCDA580D-9E3B-4B44-BD65-C8D37A0DD62D&displaylang=en


Internet Explorer 6 for Windows Server 2003:

http://www.microsoft.com/downloads/details.aspx?FamilyId=D86262D9-C66A-4608-8DBE-2492B4AFBC3B&displaylang=en


Internet Explorer 6 for Windows Server 2003 (64-Bit Edition):

http://www.microsoft.com/downloads/details.aspx?FamilyId=1AA8F5A9-71D3-48F7-BB32-F8A4D36C5FB9&displaylang=en

Microsoft reports that IE 6 SP1 and IE 6 for Windows Server 2003 are not affected by this vulnerability.

Microsoft notes that this update does not include "hotfixes" for Internet Explorer provided since the release of MS04-004. If you have received hotfixes, see the vendor's advisory for more information:

http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx

Vendor URL:  www.microsoft.com/technet/security/bulletin/ms04-025.mspx (Links to External Site)
Cause:   Boundary error
Underlying OS:  Windows (Any)

Message History:   This archive entry is a follow-up to the message listed below.
Feb 15 2004 Microsoft Internet Explorer Integer Overflow in Processing Bitmap Files Lets Remote Users Execute Arbitrary Code



 Source Message Contents

Date:  Fri, 30 Jul 2004 14:14:17 -0400
Subject:  http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx


http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx

 > Microsoft Security Bulletin MS04-025
 > Cumulative Security Update for Internet Explorer (867801)

 > Impact of Vulnerability:  Remote Code Execution

 > Maximum Severity Rating: Critical

 > Security Update Replacement: This update replaces the one that is provided in Microsoft
 > Security Bulletin MS04-004, which is itself a cumulative update.


Navigation Method Cross-Domain Vulnerability - CAN-2004-0549
	
Malformed BMP File Buffer Overrun Vulnerability - CAN-2004-0566

Malformed GIF File Double Free Vulnerability - CAN-2003-1048



Microsoft has issued the following fixes:

Internet Explorer 5.01 Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=507E71EF-076B-43C4-8028-E91FCFAB252B&displaylang=en


Internet Explorer 5.01 Service Pack 3:

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AA6F31D-7350-43F8-B72E-ED9D62577A60&displaylang=en


Internet Explorer 5.01 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=862E6914-821A-4C51-985B-C3958FAD3D4C&displaylang=en


Internet Explorer 5.5 Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=E458480C-93F6-454A-A663-FC187C18CD9B&displaylang=en


Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=4C2F8A40-1B88-4F93-98B1-1619DCFD7273&displaylang=en


Internet Explorer 6 Service Pack 1:

http://www.microsoft.com/downloads/details.aspx?FamilyId=06F49985-F19F-4B50-A75F-7636D8BEE576&displaylang=en


Internet Explorer 6 Service Pack 1 (64-Bit Edition):

http://www.microsoft.com/downloads/details.aspx?FamilyId=FCDA580D-9E3B-4B44-BD65-C8D37A0DD62D&displaylang=en


Internet Explorer 6 for Windows Server 2003:

http://www.microsoft.com/downloads/details.aspx?FamilyId=D86262D9-C66A-4608-8DBE-2492B4AFBC3B&displaylang=en


Internet Explorer 6 for Windows Server 2003 (64-Bit Edition):

http://www.microsoft.com/downloads/details.aspx?FamilyId=1AA8F5A9-71D3-48F7-BB32-F8A4D36C5FB9&displaylang=en


 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2017, SecurityGlobal.net LLC