int(3916)

Vulnerability Bulletins


Ejecución de código en Microsoft Internet Explorer

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Internet Explorer 5.01 SP4
Microsoft Internet Explorer 6 - 6 SP1
Microsoft Internet Explorer 7
HP Storage Management Appliance v2.1

Description

Se ha descubierto una vulnerabilidad en Microsoft Internet Explorer 5.01 SP4, 6 hasta la versión SP1, y 7. La vulnerabilidad reside en un error en la manera como procesa “streams” de datos.

Un atacante remoto podría ejecutar código arbitrario mediante una página Web especialmente diseñada.

El boletín MS08-024 sustituye al MS08-010.
El boletín MS08-031 sustituye al MS08-024.

Solution



Actualización de software

Microsoft (MS08-024)
Microsoft Internet Explorer 5.01 SP4 (Windows 2000 SP4) / patch IE5.01sp4-KB948881-Windows2000sp4-x86-enu
Microsoft Internet Explorer 6 SP1 (Windows 2000 SP4) / patch IE6.0sp1-KB947864-Windows2000-x86-enu
Microsoft Internet Explorer 6 (Windows XP SP2) / patch Windowsxp-kb947864-x86-enu
Microsoft Internet Explorer 6 (Windows XP SP2 64 bit) / patch WindowsServer2003.WindowsXP-KB947864-x64-enu
Microsoft Internet Explorer 6 (Windows Server 2003 SP1 y SP2 32 bit) / patch Windowsserver2003-kb947864-x86-enu
Microsoft Internet Explorer 6 (Windows Server 2003 SP1 y SP2 64 bit) / patch WindowsServer2003.WindowsXP-KB947864-x64-enu
Microsoft Internet Explorer 6 (Windows Server 2003 SP1 y SP2 Itanium) / patch Windowsserver2003-kb947864-ia64-enu
Microsoft Internet Explorer 7 (Windows XP SP2) / patch IE7-WindowsXP-KB947864-x86-enu
Microsoft Internet Explorer 7 (Windows XP SP2 64 bit) / patch IE7-WindowsServer2003.WindowsXP-KB947864-x64-enu
Microsoft Internet Explorer 7 (Windows Server 2003 SP1 y SP2 32 bit) / patch IE7-WindowsServer2003-KB947864-x86-enu
Microsoft Internet Explorer 7 (Windows Server 2003 SP1 y SP2 64 bit) / patch IE7-WindowsServer2003.WindowsXP-KB947864-x64-enu
Microsoft Internet Explorer 7 (Windows Server 2003 SP1 y SP2 Itanium) / patch IE7-WindowsServer2003-KB947864-ia64-enu
Microsoft Internet Explorer 7 (Windows Vista SP1 32 bit) / patch Windows6.0-KB947864-x86
Microsoft Internet Explorer 7 (Windows Vista SP1 64 bit) / patch Windows6.0-KB947864-x64
Microsoft Internet Explorer 7 (Windows Server 2008 32 bit) / patch Windows6.0-KB947864-x86
Microsoft Internet Explorer 7 (Windows Server 2008 64 bit) / patch Windows6.0-KB947864-x64
Microsoft Internet Explorer 7 (Windows Server 2008 Itanium) / patch Windows6.0-KB947864-ia64
http://www.microsoft.com/downloads

Hewlett-Packard
Storage Management Appliance v2.1
Instale el parche de Microsoft correspondiente a su sistema operativo.

Standar resources

Property Value
CVE CVE-2008-1085
BID 28552

Other resources

Microsoft Security Bulletin (MS08-024)
http://www.microsoft.com/technet/security/bulletin/ms08-024.mspx

Microsoft Security Bulletin (MS08-031)
http://www.microsoft.com/technet/security/Bulletin/MS08-031.mspx

HP SECURITY BULLETIN (HPSBST02329)
https://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01433452-1

Version history

Version Comments Date
1.0 Aviso emitido 2008-04-10
1.1 Aviso emitido por HP (HPSBST02329) 2008-04-23
1.2 Aviso emitido por Microsoft (MS08-031). Descripción actualizada. 2008-06-11
Ministerio de Defensa
CNI
CCN
CCN-CERT