漏洞信息详情
Microsoft Internet Explorer安全漏洞
- CNNVD编号:CNNVD-200412-657
- 危害等级: 超危
- CVE编号:
CVE-2004-1050
- 漏洞类型:
其他
- 发布时间:
2004-11-01
- 威胁类型:
远程
- 更新时间:
2021-07-27
- 厂 商:
avaya - 漏洞来源:
Berend-Jan Wever※ … -
漏洞简介
Microsoft Internet Explorer(IE)是美国微软(Microsoft)公司的一款Windows操作系统附带的Web浏览器。
Microsoft Internet Explorer是一款流行的WEB浏览器。Microsoft Internet Explorer在处理IFRAME标签的NAME属性时缺少正确的缓冲区边界检查,远程攻击者可以利用这个漏洞以IE进程权限在系统上执行任意指令。攻击者如果构建一个IFRAME标签,并在NAME属性中构建超长字符串,诱使用户访问此页面,可导致目标用户IE程序发生缓冲区溢出,精心构建页面数据,可能以IE进程权限在系统上执行任意指令。
漏洞公告
厂商补丁:
Microsoft
———
Microsoft已经为此发布了一个安全公告(MS04-040)以及相应补丁:
MS04-040:Cumulative Security Update for Internet Explorer (889293)
链接:
http://www.microsoft.com/technet/security/bulletin/ms04-040.mspx” target=”_blank”>
http://www.microsoft.com/technet/security/bulletin/ms04-040.mspx
补丁下载:
* IE6 SP1 for Windows XP, Windows 2000
http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&FamilyID=3a9dbd51-4348-4ee6-9bc1-d9a1e12963ec” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&FamilyID=3a9dbd51-4348-4ee6-9bc1-d9a1e12963ec
* IE6 SP1 for Windows 98, Windows Millennium, Windows NT4
http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&FamilyId=96DE6C13-4F67-4581-8F51-2C8A90E11C57” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&FamilyId=96DE6C13-4F67-4581-8F51-2C8A90E11C57
* IE6 6 for Windows XP Service Pack 1 (64位版本)
http://www.microsoft.com/downloads/details.aspx?familyid=1e9105cf-eb5b-4af5-b73d-03e8969e0b5c” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?familyid=1e9105cf-eb5b-4af5-b73d-03e8969e0b5c
参考网址
来源:CERT-VN
链接:http://www.kb.cert.org/vuls/id/842160
来源:CERT
链接:http://www.us-cert.gov/cas/techalerts/TA04-336A.html
来源:FULLDISC
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040
来源:CERT
链接:http://www.us-cert.gov/cas/techalerts/TA04-315A.html
来源:BID
链接:https://www.securityfocus.com/bid/11515
来源:FULLDISC
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html
来源:BUGTRAQ
链接:http://marc.info/?l=bugtraq&m=109942758911846&w=2
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/17889
来源:SECUNIA
链接:http://secunia.com/advisories/12959/
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/379261
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294