This application requires Javascript for optimal performance.

MS.IE.DHTML.Method.Heap.Memory.Corruption

Release Date

Jun 01, 2007

Severity

low

Impact

System compromise.

Description

Microsoft Internet Explorer has a heap based buffer overflow vulnerability. A remote attacker could execute arbitrary code on a victim system via a specially crafted DHTML web page. For the exploit to work the attacker must persuade the victim to open the malicious page.

Affected Products

Microsoft, Internet Explorer, 5.0.1 SP4
Microsoft, Internet Explorer, 5.0.1 SP3
Microsoft, Internet Explorer, 5.0.1 SP2
Microsoft, Internet Explorer, 5.0.1 SP1
Microsoft, Internet Explorer, 5.0.1
Microsoft, Internet Explorer, 5.5 SP2
Microsoft, Internet Explorer, 5.5 SP1
Microsoft, Internet Explorer, 5.5
Microsoft, Internet Explorer, 6.0 SP2
Microsoft, Internet Explorer, 6.0 SP1
Microsoft, Internet Explorer, 6.0

Recommended Actions

Apply patch, available from the Web site.
http://www.microsoft.com/technet/security/bulletin/MS05-014.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-0055

Reference/s

http://www.securityfocus.com/bid/12427 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/MS05-014.mspx (MS-ID)

Reference: VID-14601