[PCWorks] Internet Explorer MHTML Protocol Handler Cross-Domain Information Disclosure

  • From: "Clint Hamilton-PCWorks Admin" <PCWorks@xxxxxxxxxxxxxxxxxxxxxxxx>
  • To: "PCWorks@xxxxxxxxxxxxx" <pcworks@xxxxxxxxxxxxx>
  • Date: Wed, 13 Aug 2008 00:17:33 -0500

TITLE:
Internet Explorer MHTML Protocol Handler Cross-Domain 
Information
Disclosure

SECUNIA ADVISORY ID:
SA31415

VERIFY ADVISORY:
http://secunia.com/advisories/31415/

CRITICAL:
Moderately critical

IMPACT:
Exposure of sensitive information

WHERE:
From remote

SOFTWARE:
Microsoft Internet Explorer 7.x
http://secunia.com/product/12366/
Microsoft Internet Explorer 6.x
http://secunia.com/product/11/
Microsoft Internet Explorer 5.01
http://secunia.com/product/9/

DESCRIPTION:
A vulnerability has been reported in Internet Explorer, which 
can be
exploited by malicious people to gain knowledge of sensitive
information.

The vulnerability is caused due to an error in the MHTML 
protocol
handler when interpreting MHTML URI redirections. This can be
exploited to bypass Internet Explorer domain restrictions when
returning MHTML content via a specially crafted web page.

Successful exploitation allows reading content from another 
Internet
Explorer domain or the local system

NOTE: The vulnerability is reported in Outlook Express and 
Windows
Mail by Microsoft vulnerability as the functionality is 
provided by
these programs. However, the vulnerability is exploitable via
Internet Explorer.

SOLUTION:
Apply patches.

-- Outlook Express 5.5 SP2 --

Windows 2000 SP4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=6257bfae-35f0-4c0e-b960-bca7aa6f86f7


-- Outlook Express 6 SP1 --

Windows 2000 SP4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=dab178f7-c282-41f4-acb1-a86e6aa4c91b


-- Microsoft Outlook Express 6 --

Windows XP SP2/SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=91469f2f-461c-4a67-8738-d42520427f6b

Windows XP Professional x64 Edition (optionally with SP2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=2220aece-79d2-426f-90ec-24a17470567a

Windows Server 2003 SP1/SP2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=30f2244a-f6fd-4fc1-a871-abf6958cb660

Windows Server 2003 x64 Edition (optionally with SP2):
http://www.microsoft.com/downloads/details.aspx?FamilyId=3287f006-cbb2-4c6d-820c-32833e08035a

Windows Server 2003 with SP1/SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=c8570e40-355b-4a9b-933d-53ae021cbda5


-- Windows Mail --

Windows Vista (optionally with SP1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=3851bcf8-f971-4d38-b27f-97396854aac0

Windows Vista x64 Edition (optionally with SP1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=3bf7eb8a-b347-4661-be2d-682adc713769

Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=dc3c4b63-acd3-4469-8d47-e0562d99ee65

Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=5f973f54-2322-4b41-8c1a-3e712c0da8ae

Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9226cd85-1445-4976-a126-757c5d142ffd

ORIGINAL ADVISORY:
MS08-048 (KB951066):
http://www.microsoft.com/technet/security/Bulletin/MS08-048.mspx


=========================
The list's FAQ's can be seen by sending an email to 
PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line.

To unsubscribe, subscribe, set Digest or Vacation to on or off, go to 
//www.freelists.org/list/pcworks .  You can also send an email to 
PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line.  Your 
member list settings can be found at 
//www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks .  Once logged in, you have 
access to numerous other email options.  

The list archives are located at //www.freelists.org/archives/pcworks/ .  
All email posted to the list will be placed there in the event anyone needs to 
look for previous posts.
-zxdjhu-

Other related posts:

  • » [PCWorks] Internet Explorer MHTML Protocol Handler Cross-Domain Information Disclosure