(Vendor Issues Killbit Workaround for Download) Microsoft Internet Explorer 'javaprxy.dll' COM Object Exception Handling Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1014394 |
|
SecurityTracker URL: http://securitytracker.com/id/1014394
|
|
CVE Reference:
CVE-2005-2087
(Links to External Site)
|
Date: Jul 5 2005
|
Impact:
Denial of service via network, Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 6.0 SP1 and prior versions; Tested on 6.0.2900.2180
|
Description:
A vulnerability was reported in Microsoft Internet Explorer in 'javaprxy.dll'. A remote user can cause the target user's browser to crash or execute arbitrary code.
A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a heap overflow in 'javaprxy.dll' and cause the target user's browser to crash. Specially crafted object tags can cause certain COM componenets to crash.
It is also possible to overwrite a function pointer to execute arbitrary code.
A demonstration exploit from FrSIRT is available at:
http://www.frsirt.com/exploits/20050702.iejavaprxyexploit.pl.php
The vendor was notified on June 17, 2005.
sk0L and Martin Eiszner from SEC-CONSULT discovered this vulnerability.
|
Impact:
A remote user can cause the target user's browser to crash.
A remote user can execute arbitrary code on the target system.
|
Solution:
Microsoft has issued a killbit package to disable the vulnerable COM object.
For Internet Explorer 5.01 Service Pack 3 on Microsoft Windows 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=25982E02-EC6D-44CE-82DE-12DDEF1ADDD6&displaylang=en
For Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack:
http://www.microsoft.com/downloads/details.aspx?FamilyId=25982E02-EC6D-44CE-82DE-12DDEF1ADDD6&displaylang=en
For Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 3, on Microsoft Windows 2000 Service Pack 4, or on Microsoft Windows XP Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2A506C16-01EF-4060-BCF8-6993C55840A9&displaylang=en
For Internet Explorer 6 for Microsoft Windows XP Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=C1381768-6C6D-4568-97B1-600DB8798EBF&displaylang=en
For Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=F368E231-9918-4881-9F17-60312F82183F&displaylang=en
For Internet Explorer 6 for Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium), Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=D785F9AB-DBE9-4272-A87E-64205690F98E&displaylang=en
For Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition, and Microsoft Windows XP Professional x64 Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=68209225-A682-4008-A22B-881C401486F7&displaylang=en
For Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=06F8CD1B-93A0-4522-AF7D-603DD5C2BACB&displaylang=en
For Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Millennium Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2A506C16-01EF-4060-BCF8-6993C55840A9&displaylang=en
For additional information, see the vendor's advisory at:
http://www.microsoft.com/technet/security/advisory/903144.mspx
|
Vendor URL: www.microsoft.com/technet/security/advisory/903144.mspx (Links to External Site)
|
Cause:
Exception handling error
|
Underlying OS:
Windows (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Tue, 5 Jul 2005 18:07:46 -0400
Subject: http://www.microsoft.com/technet/security/advisory/903144.mspx
|
> Disable attempts to instantiate the Javaprxy.dll control in Internet Explorer by
> setting the kill bit for the control using one of the following options:
>
> Option 1: Disable Javaprxy.dll by using the registry key update that is available
> from the Microsoft Download Center by visiting the Microsoft Web site for the
> corresponding version of IE:
>
> Note The download will be labeled as KB903235
•
Internet Explorer 5.01 Service Pack 3 on Microsoft Windows 2000 Service Pack 3
http://www.microsoft.com/downloads/details.aspx?FamilyId=25982E02-EC6D-44CE-82DE-12DDEF1ADDD6&displaylang=en
•
Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack
http://www.microsoft.com/downloads/details.aspx?FamilyId=25982E02-EC6D-44CE-82DE-12DDEF1ADDD6&displaylang=en
•
Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 3, on Microsoft Windows 2000 Service Pack 4, or on Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=2A506C16-01EF-4060-BCF8-6993C55840A9&displaylang=en
•
Internet Explorer 6 for Microsoft Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=C1381768-6C6D-4568-97B1-600DB8798EBF&displaylang=en
•
Internet Explorer 6 for Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=F368E231-9918-4881-9F17-60312F82183F&displaylang=en
•
Internet Explorer 6 for Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium), Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyId=D785F9AB-DBE9-4272-A87E-64205690F98E&displaylang=en
•
Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition, and Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=68209225-A682-4008-A22B-881C401486F7&displaylang=en
•
Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=06F8CD1B-93A0-4522-AF7D-603DD5C2BACB&displaylang=en
•
Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Millennium Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=2A506C16-01EF-4060-BCF8-6993C55840A9&displaylang=en
|
|