New IE graphics vulnerability ( Archived) (10)

Sep 19, 2006 2:03 PM CST New IE graphics vulnerability
TheProfessor
TheProfessorTheProfessorPandoras Box, USA91 Threads 4,746 Posts
Cited from FRSIRT - parts excluded due to forum rules (namely other reference URLs)

...

Advisory ID : FrSIRT/ADV-2006-3679
CVE ID : CVE-2006-3866
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-09-19

Technical Description

A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to crash a vulnerable browser or take complete control of an affected system. This flaw is due to a buffer overflow error in the Microsoft Vector Graphics Rendering library (Vgx.dll) when processing Vector Markup Language (VML) documents containing a "rect" shape with an overly long "fill" method, which could be exploited by attackers to cause a denial of service or execute arbitrary commands by convincing a user to visit a malicious Web page.

FrSIRT has confirmed this vulnerability on a fully patched Windows XP SP2 system. This issue is currently being exploited in the wild by malicious web sites.

Affected Products

Microsoft Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4
Microsoft Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4
Microsoft Internet Explorer 6 Service Pack 1 on Microsoft Windows XP Service Pack 1
Microsoft Internet Explorer 6 for Microsoft Windows XP Service Pack 2
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 Service Pack 1
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 (Itanium)
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 with SP1 (Itanium)
Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition
Microsoft Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition
Microsoft Internet Explorer 6 Service Pack 1 on Microsoft Windows 98
Microsoft Internet Explorer 6 Service Pack 1 on Microsoft Windows 98 SE
Microsoft Internet Explorer 6 Service Pack 1 on Microsoft Windows Millennium Edition

Solution

The FrSIRT is not aware of any official supplied patch for this issue.

Disable Active Scripting in the Internet and Local intranet security zones :

- In Internet Explorer, click Internet Options on the Tools menu
- Click the Security tab
- Click Internet, and then click Custom Level
- Under Settings, in the Scripting section, under Active Scripting, click Disable, and then click OK
- Click Local intranet, and then click Custom Level
- Under Settings, in the Scripting section, under Active Scripting, click Disable, and then click OK
- If you are prompted to confirm that you want to change these settings, click Yes
- Click OK to return to Internet Explorer

Note : Disabling Active Scripting may cause some Web sites to work incorrectly.
------ This thread is Archived ------
Sep 19, 2006 2:06 PM CST New IE graphics vulnerability
catwm
catwmcatwmSomewhere in the middle, Florida USA48 Threads 6,683 Posts
Given the choices above what would you do Prof?
------ This thread is Archived ------
Sep 19, 2006 2:08 PM CST New IE graphics vulnerability
nwnstar
nwnstarnwnstarConway, USA38 Threads 5,464 Posts
ahem. switch to mozilla firefox.
------ This thread is Archived ------
Sep 19, 2006 2:08 PM CST New IE graphics vulnerability
TheProfessor
TheProfessorTheProfessorPandoras Box, USA91 Threads 4,746 Posts
I would never use IE, and use Firefox. It's faster, more stable, and is patched/modified all the time by people who care about it - not people who want to make $ off of it like Microsoft does.

Firefox > IE

I'm in the process of starting a project that J mentioned to me a bit ago - I'm working on writing a browser in DarkBasic which won't have any issues that IE does due to it being based on a completely different graphics set, and isn't recycled code.
------ This thread is Archived ------
Sep 19, 2006 2:09 PM CST New IE graphics vulnerability
nwnstar
nwnstarnwnstarConway, USA38 Threads 5,464 Posts
i don't see ie7 listed, however...
------ This thread is Archived ------
Sep 19, 2006 2:09 PM CST New IE graphics vulnerability
TheProfessor
TheProfessorTheProfessorPandoras Box, USA91 Threads 4,746 Posts
This isn't the one I mentioned in the other thread - this is another vulnerability that surfaced today.
------ This thread is Archived ------
Sep 19, 2006 2:11 PM CST New IE graphics vulnerability
nwnstar
nwnstarnwnstarConway, USA38 Threads 5,464 Posts
thanks.
------ This thread is Archived ------
Sep 19, 2006 4:12 PM CST New IE graphics vulnerability
MichaelH
MichaelHMichaelHNowhere, Indiana USA24 Threads 620 Posts
I've told people for years not to use IE. Every other week someone finds a glitch in it to cause problems and exploit your PC. I upgraded to IE7 just in case, but I don't even use it.

Firefox and Opera, and I'm sure other browsers, are totally free. Plus they upgrade often.
------ This thread is Archived ------
Sep 19, 2006 4:28 PM CST New IE graphics vulnerability
Illuminate
IlluminateIlluminateKathleen, Georgia USA21 Threads 1,878 Posts
You got that right....tis why I swithched over to firefox.
------ This thread is Archived ------
Sep 19, 2006 8:33 PM CST New IE graphics vulnerability
Jonquille
JonquilleJonquillePeace is its own reward, Ontario Canada98 Threads 897 Posts
I've been on Firefox for some time now. Thanks for the heads-up.
------ This thread is Archived ------
Post Comment - Post a comment on this Forum Thread

This Thread is Archived

This Thread is archived, so you will no longer be able to post to it. Threads get archived automatically when they are older than 3 months.

« Go back to All Threads
Message #318

Stats for this Thread

623 Views
9 Comments
by TheProfessor (91 Threads)
Created: Sep 2006
Last Viewed: May 8
Last Commented: Sep 2006

Share this Thread

We use cookies to ensure that you have the best experience possible on our website. Read Our Privacy Policy Here