HZGN.COM
welcome to my space
X
Search:  
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
Welcome to:hzgn.com
 HOME   CERT Warns of Another Security Flaw in IE
CERT Warns of Another Security Flaw in IE
Published by: jack 2008-11-18
A group of Russian researchers from SECURITY.NNOV has uncovered a new flaw in Microsoft Internet Explorer that would allow an attacker to execute arbitrary code on a victim's system when the victim visits a Web page or views an HTML email message.

The Computer Emergency Response Team Coordination Center (CERT/CC), which issued an advisory about the flaw Monday, said the buffer overflow vulnerability would allow the attacker the system privileges of the victim and noted that the flaw could be exploited to distribute viruses, worms or other malicious code.

CERT attributed the vulnerability to Internet Explorer's improper handling of the SRC attribute of the directive, which can be used to include arbitrary objects in HTML documents. Common types of embedded objects include multimedia files, Java applets and ActiveX controls. The SRC attribute specifies the source path and filename of an object.

CERT said an HTML document, like a Web page or HTML email message, which contains a crafted SRC attribute can trigger a buffer overflow, executing code with the privileges of the user viewing the document. Microsoft Internet Explorer, Outlook and Outlook Express are all vulnerable. Other applications which use the Internet Explorer HTML rendering engine, such as Windows compiled HTML help (.chm) files and third-party email clients, may also be vulnerable.

US-CERT Cyber Security Bulletin SB05-188 -- Summary of Security Items ::
A reliable exploit for the flaw was created in less than 10 hours. Another slight variant of the mass-mailing worm that utilizes an IRC backdoor
http://www.us-cert.gov/cas/bulletins/SB05-188.html
HOME
Securing Your Web Browser::
the CERT/CC held a workshop to analyze security in ActiveX. is another scripting language that is unique to Microsoft Windows Internet Explorer.
http://www.cert.org/archive/pdf/browser_security0601.pdf
HOME
Microsoft has already released a patch which protects against the vulnerability and some other recently discovered flaws.

CERT also recommended disabling ActiveX controls and plugins, or, at a minimum, disabling the "Run ActiveX Controls and Plugins" security option in the Internet Zone and the zone used by Outlook or Outlook Express. That option is already disabled in the "High" zone security setting.

CERT also suggested installing the Outlook Email Security Update, which configures Outlook to open email messages in the Restricted Sites Zone, in which the "Run ActiveX Controls and Plugins" security option is disabled by default.


W3C Removes RAND From Patent Policy
BEA Systems Spices Up Java 'The Cajun Way'

#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about CERT Warns of Another Security Flaw in IE , Please add it free.

About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
Copyright© 2008 hzgn.com All Rights Reserved
Site made&Support support@hzgn.com    E-mail: web@hzgn.com