Microsoft IE浏览器注册向导缓冲区溢出漏洞

漏洞信息详情

Microsoft IE浏览器注册向导缓冲区溢出漏洞

漏洞简介

Internet Explorer 4.01版本和 5版本的Registration Wizard ActiveX控件(regwizc.dll, InvokeRegWizard) 3.0.0.0中存在缓冲区溢出漏洞。远程攻击者利用该漏洞执行任意命令。

漏洞公告

Microsoft has released a patch for this vulnerability:
– Internet Explorer 4.01 for Intel:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE401/ImportExportFavorites-fix/x86/q241361.exe
– Internet Explorer 4.01 for Alpha:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE401/ImportExportFavorites-fix/Alpha/q241361.exe
– Internet Explorer 5 for Intel:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE50/ImportExportFavorites-fix/x86/q241361.exe
– Internet Explorer 5 for Alpha:
ftp://ftp.microsoft.com/peropsys/ie/ie-public/fixes/usa/IE50/ImportExportFavorites-fix/Alpha/q241361.exe

参考网址

来源:US-CERT Vulnerability Note: VU#37556
名称: VU#37556
链接:http://www.kb.cert.org/vuls/id/37556

来源: BID
名称: 671
链接:http://www.securityfocus.com/bid/671

来源: XF
名称: ie-registration-wiz-bo(3311)
链接:http://xforce.iss.net/xforce/xfdb/3311

来源: BUGTRAQ
名称: 19990924 Several ActiveX Buffer Overruns
链接:http://www.securityfocus.com/archive/1/28719

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享