Vulnerabilities > CVE-2007-0943 - Unspecified vulnerability in Microsoft IE and Internet Explorer
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS07-045.NASL |
description | The remote host is missing IE Cumulative Security Update 937143. The remote version of IE is potentially vulnerable to several flaws that may allow an attacker to execute arbitrary code on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25883 |
published | 2007-08-14 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25883 |
title | MS07-045: Cumulative Security Update for Internet Explorer (937143) |
code |
|
Oval
accepted | 2007-09-27T08:57:41.035-04:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
definition_extensions |
| ||||||||
description | Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers. | ||||||||
family | windows | ||||||||
id | oval:org.mitre.oval:def:1673 | ||||||||
status | accepted | ||||||||
submitted | 2007-08-15T09:28:35 | ||||||||
title | CSS Memory Corruption Vulnerability | ||||||||
version | 70 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 25288 CVE(CAN) ID: CVE-2007-0943 Internet Explorer是微软发布的非常流行的WEB浏览器。 IE 5.0在解析样式表(CSS)文件时存在安全漏洞,远程攻击者可能利用此漏洞控制用户系统。 由于没有对数据指针进行必要的检查,当处理特殊格式的CSS文件时,会造成指针越界,并改写内存数据。通过精心构造数据,攻击着可能远程执行任意指令。攻击者可以创建恶意WEB页面诱使用户访问,从而以该用户身份执行任意任意命令。如果该用户是管理员,则攻击者可以完全控制用户所在系统。即使将IE的安全级别设置为高,用户仍然会受此漏洞影响。 Microsoft Internet Explorer 5.01 Microsoft已经为此发布了一个安全公告(MS07-045)以及相应补丁: MS07-045:Cumulative Security Update for Internet Explorer (937143) 链接:<a href="http://www.microsoft.com/technet/security/Bulletin/MS07-045.mspx?pf=true" target="_blank">http://www.microsoft.com/technet/security/Bulletin/MS07-045.mspx?pf=true</a> |
id | SSV:2120 |
last seen | 2017-11-19 |
modified | 2007-08-17 |
published | 2007-08-17 |
reporter | Root |
title | Microsoft IE CSS字符串内存破坏漏洞(MS07-045) |
References
- http://www.nsfocus.com/english/homepage/research/0701.htm
- http://www.us-cert.gov/cas/techalerts/TA07-226A.html
- http://www.securityfocus.com/bid/25288
- http://www.osvdb.org/36397
- http://securitytracker.com/id?1018562
- http://secunia.com/advisories/26419
- http://www.vupen.com/english/advisories/2007/2869
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1673
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045