SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Browser)  >   Microsoft Internet Explorer (IE) Vendors:   Microsoft
Microsoft Internet Explorer Bugs Let Remote Users Spoof the Address Bar and Execute Arbitrary Code
SecurityTracker Alert ID:  1018788
SecurityTracker URL:  http://securitytracker.com/id/1018788
CVE Reference:   CVE-2007-1091, CVE-2007-3826, CVE-2007-3892, CVE-2007-3893   (Links to External Site)
Date:  Oct 9 2007
Impact:   Execution of arbitrary code via network, Modification of system information, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): 5.01 SP4, 6, 6 SP1, 7
Description:   Several vulnerabilities were reported in Microsoft Internet Explorer. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can spoof the address bar.

A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a script error exception handling flaw and execute arbitrary code on the target system [CVE-2007-3893]. The code will run with the privileges of the target user.

A remote user can create specially crafted HTML that, when loaded by the target user, will spoof aspects of the target user's browser interface, including the address bar.

Pierre Geyer of next.motion OHG, Carsten H. Eiram of Secunia Research, and Jakob Balle of Secunia Research reported these vulnerabilities.

Impact:   A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can create HTML that, when loaded by the target user, will spoof the address bar.

Solution:   The vendor has issued the following fixes as part of a cumulative update. This bulletin replaces MS07-045.

2000 SP4 - Microsoft Internet Explorer 5.01 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=95827F3F-A984-4E34-A949-D16A0614121A

2000 SP4 - Microsoft Internet Explorer 6 Service Pack 1:

http://www.microsoft.com/downloads/details.aspx?FamilyId=DF3BA596-7C5B-4151-9884-6957AA884AAB

XP SP2 - Microsoft Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=513A8320-6D36-4FC9-A38A-867192B55B53

Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Microsoft Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=AE8A26D8-1910-4B8C-8A73-6E2FA6B5B29F

2003 SP1 and SP2 - Microsoft Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=4AEFAA38-8757-4E6E-8924-57CABD1C2FC3

Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Microsoft Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=88ABA9DD-653B-4CDF-A513-CCA32A7D7E41

Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems - Microsoft Internet Explorer 6:

http://www.microsoft.com/downloads/details.aspx?FamilyId=309A8F10-C7EA-4961-A969-092B0C4D7BBC

XP SP2 - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=4CA0AC93-BF51-40FE-A1BA-CB3E0A36D8B5

Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2 - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=DBD284D0-2664-42A4-AD16-A0535244C81C

Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=0A31C451-32F4-4551-AE45-D600F8B3B11B

Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=C1915633-D181-4CA1-A4F0-7CA0F865AA72

Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=093A2250-3BE3-494F-80E0-89CA7217030F

Vista - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=86392E8D-098C-427F-A233-699CDB9375AE

Vista x64 - Windows Internet Explorer 7:

http://www.microsoft.com/downloads/details.aspx?FamilyId=62490E6D-0A21-4A15-90BD-63CA8F8886B6

A restart is required.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/bulletin/ms07-057.mspx

Vendor URL:  http://www.microsoft.com/technet/security/bulletin/ms07-057.mspx (Links to External Site)
Cause:   Access control error, State error
Underlying OS:   Windows (2000), Windows (2003), Windows (Vista), Windows (XP)

Message History:   None.


 Source Message Contents

Date:  Tue, 9 Oct 2007 13:52:20 -0400
Subject:  Microsoft Security Bulletin MS07-057 - Critical: Cumulative Security Update for Internet Explorer (939653)


http://www.microsoft.com/technet/security/bulletin/ms07-057.mspx

CVE-2007-1091
CVE-2007-3826
CVE-2007-3892
CVE-2007-3893

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2014, SecurityGlobal.net LLC