TUCoPS :: Browsers :: b06-4384.htm

Internet Explorer 'Crash' is Exploitable
EEYE:ALERT: MS06-042 Related Internet Explorer 'Crash' is Exploitable
EEYE:ALERT: MS06-042 Related Internet Explorer 'Crash' is Exploitable



This is a multi-part message in MIME format.

------_=_NextPart_001_01C6C62A.6571501B
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

MS06-042 Related Internet Explorer 'Crash' is Exploitable

Date:
August 22, 2006

Severity:
High

Systems Affected:
Windows 2000 with IE6 SP1 and MS06-042 hotfix installed
Windows XP SP1 with IE6 SP1 and MS06-042 hotfix installed

Overview:
On August 8th Microsoft released MS06-042 which was a cumulative update
for Internet Explorer[1]. Over the course of a few days after the
release of this patch various Internet Explorer users and businesses
started to experience Internet Explorer crashing problems when viewing
certain websites[2]. Later on August 11th Microsoft created a knowledge
base article which talked about problems with the MS06-042 patch and how
Internet Explorer could crash when viewing some web pages that used
compression[3]. This Microsoft KB article referenced a patch, which
could be requested through Microsoft Product Support Services, that
would fix the "crashing" bug. There was further discussion about the
extent of the crashes and widespread nature of the bug on places such as
SANS and various patch and IT mailing lists[4]. Because of the
widespread discussions and number of people experiencing the Internet
Explorer crash various security researchers, including eEye, decided to
investigate as a lot of times crashes can be exploitable. 

We have since found that indeed the reason that people are experiencing
Internet Explorer browser crashes is certain websites, that use
compression (as stated by Microsoft[5]), are causing a non-malicious
buffer overflow to occur within Internet Explorer. After investigating
and confirming that indeed this is an exploitable condition we are
alerting people to the true severity of these "crashing" problems that
people are experiencing, so that they can take the appropriate
mitigation steps as need be. 

This information is already known in various research circles and also
with exploit writers. So it is important that IT administrators
understand the true threat of this problem that this is not simply a
crashing bug, as Microsoft has been incorrectly misrepresenting it, but
in fact that it is an exploitable security bug. Researchers and exploit
developers know this, therefore it is extremely important that IT
administrators are told what really is going on.

Prevention:
Windows 2000 IE6 SP1 Systems
Patch: Microsoft created and released a non-public patch on August 11th.
You can find out more about this patch here:
http://support.microsoft.com/?kbid=923762. This patch can only currently 
be obtained through the Microsoft PSS process. However, Microsoft does
plan to eventually release a public patch through Windows Update etc...
Workaround: Disable HTTP1.1 functionality as outlined by Microsoft in
their knowledge base article: http://support.microsoft.com/?kbid=923762. 
Please review the caveats of doing this as outlined by Microsoft.

Windows XP SP1 IE6 SP1 Systems
Patch: The best way to protect your XP systems is to upgrade to Windows
XP SP2 as it is protected against this vulnerability. Also support for
XP SP1 ends in October and there are huge security benefits to XP SP2 so
hopefully your're already migrated to it. If you are not however and you
are stuck on XP SP1 then you can use the Microsoft Knowledge base patch
which was released on August 11th through the PSS process.
http://support.microsoft.com/?kbid=923762 
Workaround: Disable HTTP1.1 functionality as outlined by Microsoft in
their knowledge base article: http://support.microsoft.com/?kbid=923762. 
Please review the caveats of doing this as outlined by Microsoft.

Credit: Derek Soeder (eEye)

Links:
[1] - MS06-042 Bulletin -
http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx 
[2] - SANS - http://isc.sans.org 
[3] - Microsoft KB Article - http://support.microsoft.com/?kbid=923762 
[4] - SANS Thread - http://isc.sans.org/diary.php?storyid=1588 
[5] - http://blogs.technet.com/msrc/archive/2006/08/16/447023.aspx 

Copyright (c) 1998-2006 eEye Digital Security
Permission is hereby granted for the redistribution of this alert
electronically. It is not to be edited in any way without express
consent of eEye. If you wish to reprint the whole or any part of this
alert in any other medium excluding electronic medium, please email
alert@eEye.com for permission. 

Disclaimer
The information within this paper may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are no warranties, implied or express, with regard to this information.
In no event shall the author be liable for any direct or indirect
damages whatsoever arising out of or in connection with the use or
spread of this information. Any use of this information is at the user's
own risk.

------_=_NextPart_001_01C6C62A.6571501B
Content-Type: application/ms-tnef;
	name="winmail.dat"
Content-Transfer-Encoding: base64

eJ8+IisUAQaQCAAEAAAAAAABAAEAAQeQBgAIAAAA5AQAAAAAAADoAAEIgAcAGAAAAElQTS5NaWNy
b3NvZnQgTWFpbC5Ob3RlADEIAQ2ABAACAAAAAgACAAEEgAEARgAAAEVFWUU6QUxFUlQ6IE1TMDYt
MDQyIFJlbGF0ZWQgSW50ZXJuZXQgRXhwbG9yZXIgJ0NyYXNoJyBpcyBFeHBsb2l0YWJsZQCsFgEF
gAMADgAAANYHCAAWAA0AIQAnAAIAUgEBIIADAA4AAADWBwgAFgANACIAKgACAFYBAQmAAQAhAAAA
NDYwMDJCMkFGOUY5Mzk0QTg1QzIyRUMxOEQwMURBRTMANwcBA5AGAHQQAAAvAAAACwACAAEAAAAD
ACYAAAAAAAMANgAAAAAAQAA5AKDNV0AqxsYBHgA9AAEAAAABAAAAAAAAAAIBRwABAAAAOwAAAGM9
VVM7YT0gO3A9ZUV5ZSBEaWdpdGFsIFNlYztsPUFWLU1BSUwwMS0wNjA4MjIyMDM0NDFaLTMxMjMA
AB4AcAABAAAARgAAAEVFWUU6QUxFUlQ6IE1TMDYtMDQyIFJlbGF0ZWQgSW50ZXJuZXQgRXhwbG9y
ZXIgJ0NyYXNoJyBpcyBFeHBsb2l0YWJsZQAAAAIBcQABAAAAFgAAAAHGxipATqpIjqo2yErYjvZY
3/JTc9QAAB4AGgwBAAAADgAAAE1hcmMgTWFpZmZyZXQAAAAeAB0OAQAAAEYAAABFRVlFOkFMRVJU
OiBNUzA2LTA0MiBSZWxhdGVkIEludGVybmV0IEV4cGxvcmVyICdDcmFzaCcgaXMgRXhwbG9pdGFi
bGUAAAACAQkQAQAAAIkKAACFCgAAJBQAAExaRnWP1f/sAwAKAHJjcGcxMjXiMgNDdGV4BUEBAwH3
/wqAAqQD5AcTAoAP8wBQBFY/CFUHshElDlEDAQIAY2jhCsBzZXQyBgAGwxEl9jMERhO3MBIsETMI
7wn3tjsYHw4wNREiDGBjAFBzCwkBZDM2FlALpgXRMJA2LTA0FEBSZQtgcQ6wZCBJAjAEkRQgIBxF
eAtQBbASgSdDcmBhc2gnIAQAHoRpuQGRbGUKogqECoBEHbGCOiCEQXVndXMFQOgyMiwiUDAdECCK
BmASdgZxdHkhhUhpZ8poIut5IjBlbRCxASAXBZAdwSGFVwuAZG93TwQgIqEWUAPwdGgd8EXiNgYA
UDEgAHAd4Bz35GhvADBpeB+QAIABkM5sIGALMSbKWFAoUyffVyjvKfwghE8jwXYIkHetIYVPA6Ah
9Tgr4U0N4OkDYHNvAYAgGCAgYB9Qsx3RHPd3aA3gK/B3H1BBLIAgY3VtdR2haaEjwCB1cGQdsSAC
EIMFwB4PWzFdLiAvIr4gK+A0AAWgCHAUECAxUP8zQSYwB+A0QCWgLIABgDZVXzGVNyIr4B+hCrB0
MuF2/QrAaQhgBCA03zQQFBAUAP0sg2IiIAuAB5AUEAQgKgGjACAd0XRvIA7AcAZxfQnwYzQAOp8z
YB9CC4Bn/zmgA2AgUSXhMrAJ8DoAL3GfP9I+MAAgC3ErsGViAJDRDrBzWzI2AUwdsQXA8wIgMDYx
MTDLBQAxwB3CWTNQa24nQCpBZzQAYr848j0hDeAgYDKlKhFrRQL9BuB1BUBAGCvSNoIc9zm03yyS
LWAH4D5vNrJsHeA/g/9AnDFAB4BB4jmhRcAEICvgfx2wO6JL4QNwQBA8oTpAbjRbMzYBVDlyMPhL
Qv9GNxggJjAYID4hRRI5syKA6zK0S6RiOJJxClAlsT1hrmgDYCIAMNpQA2BkGtD1BUBTNCBwF8EG
Ui9gPjB2cyKATiN3S7MtkjaCInU/hiI8QWdPolGRMwNm9whwNoEFwGQEADNwTyNHhf82gg7BCfAF
QDkzNqEfQgeRVyySA/ABAHNO8WEd4G7/HbAIcDkVRdEiAEMSC1FWoc888BrQSeEGQUFOBfAskuM6
FkmoSVQgAMADED/SV2IwIjBCYDQ2AUIFkGHfO7Fb9l05Wkg79G4zgFNg90MBN0A90G8LUFtyPdU/
0v82gkqPS/U6FhQQM3Aj4jGBfxQQCsAT0DvRIoALgEaAdcNaQD/hZUV5ZSKABYH/XUE9YwuAI8Ai
MCSgNFIzI/8XsFvkB3NcdmNAA6BTYT2x9yAGNhAgilc0ABPgM/E8cfs+MQIQdSyhTiMnEQngVBL/
OJIfUEMhTiNmZQrAZr1n7/88QANgJ1A/VgeRH6FBflbVc2NiTskgKDMhKgEdwmLDalAw91s1XSki
gHTCz2NCP9IzUEVgbi0AwGIwv2dQOlI8UCYhQwEjwWYXsPMH4D2Bb2NqASuzQcF13382ECYQODJs
+HzjLKEFoG75LZBybWdkcrofoR+hA5H/b8mCwlpAM9BDIUHwdLMHQJ9BgT/TZnQ9gTaCdHIKUP9p
0SPEW/U3AVgpQBd0D2bp/yKAMUBOFDaBalBvUgGQR1D9NnNhVfADYEAQBzA0YYMw94IEQyElsXAz
MQQgHlB7En9wbU/DC4A0kQDAhgOEkmz/XZJqUEVSkqFA0TolanYzYP+DEEaBO/QHQIzBK8NvxSuw
9yPhO9E2EFNs0XLBd9FO4P8XwQBwWzJOQWHRXbCDMWKR/x9APYA74XJRO9GYYXM0iDP/VDFE0Tko
QCSM5oRkRWAFQPsAkE7gbGpQM1E/lljRfEH/T/oT4H4BCeFrMgWwGCAmUPueIYMwcxggTvJbwT/S
ICD/IoA8UHLCNIAA0JiVl7SEzf9p51jTHYBqlyyDlnYBACPA/xewPdEEIEVSOVNW0lGRNJH/NACX
tA7BGCAHgJ4hmB+ZLv90wj2AS9EysE5BRMEqMKpR3QQgZyAQP+ECIC4gilVQ/yOxohECICafJ6Es
FiWVrvV9OcI6RA9FESyhMZd9JHC+dQJgDeA5pUMsNhBZCGD/b0MtkCyhR7IEYIaSWwU5hwtZMrLQ
aAJAcDovL1tfoFXzLoMwMRUuTsEvCD9rYl1APTkyM/g3NjJPpTm0b1ICIJ4h/2oBUaGhMlNhQDBB
olQJSNO9VMhTBfBAEVahl1FIJ0D/I7IigDD4JzAHkQtRc+E9kf2vgnWtgzi2UhG1WlQ2JwbmVTQ0
FCBjLscgsAUFsG5rCsByQrLQRAQAhWNI9FRULGAuLHBZwD4ghgL/fZFqQTMhR7FiMXsdk8I2gb+D
EEVPRlS5z7rfu+lQONT/r2EvcTZ0cZEdsMphN0AnMP9nZKPyym/PFXCbKuyxP7JJ/1khU1EiMTMQ
alA9gUARDrDtVaF5CGErQnMlpR+hPYH/NCAJwF2wh6Mq2xRAMyGXtN/ZJUUCbWAp4jlUdjOgHlD/
H0C70MoCgTGV4s5lNIMrVf0J8GSR4jYgJlBAMBKBmpX7hpJZUWgiAKT6CfABECAg/9qz3DWMwS1g
PdBZwK2S2aL+J4aTkxSDMNshPUUgIDYQ/kk3QNmhi5OdokpBI7Isg/foBiIwGtBrQxIrVTaBA6Dv
6AJvUmNiv7xLzIw5tDK4/zGXQy2/OsCbzf/PD7wFx1//yG/Jf9Nfy5/Mr82/8s/P3//Q79H/0w/U
HyCTHzAJgCAgv/WBUZHqQJeACYASgShr4sopIIpMC4BrcyGFNeH0IC0c6ELlgRQgQcEGEN37JXcH
4PwN2VFoHlH7gHVp9S8Gxi8c9vwAXXB4vwV1QoAGAWAjB1daUS71wPXeEC7gcGcFdU+ABgJQKv8Q
0EZkB1f7n/yvBXVi4AwG70/AXZMMjw2SL1pAlMDfYLBwaHA/IjDgcHm74fAxNTg4BXV8EAdI9eB8
b2eXUAkFEYMl4GrALwuUwjPhLyKiLzA4L0IxGiA0NDcwvCAu7x9QC1YCReVAeZcAJLBEkAgoYylD
sDk5OC3XIqJr0/WRZyAhbFZBagT/rvV2AKFxWqNP4Vkye0HbIb914VeB4HE4dFpBiDBporH/WrI5
NobDPaDEMCZQjpCr0P9vUK2R57GXw52iPYFvkoXh/zHxQcGq0PhQ2LIrwkeyPbH/TwKCwqHyNyJr
4ue3K8BMMf89gaGiceBbNDKwrNA3EeHy//hQBGGbuCMEJdVuEFoCTVD/WkAzgD2ha2cjdy0FwdBm
ke848tpgYhGGtEAoM/yxNIN/PdEfda6L9aFGgL7QTVBy/5FWqVGSGX+1OWU90WHxjXF/oCA/4GPy
JqSdoVaR/bBV/zkJkgongkZgXgBCQZ5Af2D/j/CagXID4IBjYiXTD1BgUP5JYFCFt1kG6ERZcaDw
qtH//nBrEp4B/nC3weCAJwVSgfeWMgKw3eBybKM4DuexWtD/PRGvc3rAoCAG4I4UJtAmsP920Vlg
YjCFY+BiJgJaQKEC/yqSxhFEVMagYgBN4q0SAZD/6PSXAHzTWxL/cUSzgsJ2IP/205YUXDJjY+CA
XXU33zwy/kEmEWNnkd+eQFs0Y2HmAFcAYZOhRrFrroV9TzAAAAAeADUQAQAAAEcAAAA8QTY0MUNF
QUREQkFFQUU0Qzk2RkM1QkY4NTQ2OTUyNjgwMTQ1M0EzMkBhdi1tYWlsMDEuY29ycC5pbnQtZWV5
ZS5jb20+AAADAIAQ/////x8A8xABAAAAnAAAAEUARQBZAEUAJQAzAEEAQQBMAEUAUgBUACUAMwBB
ACAATQBTADAANgAtADAANAAyACAAUgBlAGwAYQB0AGUAZAAgAEkAbgB0AGUAcgBuAGUAdAAgAEUA
eABwAGwAbwByAGUAcgAgACcAQwByAGEAcwBoACcAIABpAHMAIABFAHgAcABsAG8AaQB0AGEAYgBs
AGUALgBFAE0ATAAAAAsA9hAAAAAAQAAHMMHtbmUqxsYBQAAIMJEAgmUqxsYBAwDeP59OAAADAPE/
CQQAAB4A+D8BAAAADgAAAE1hcmMgTWFpZmZyZXQAAAACAfk/AQAAAG4AAAAAAAAA3KdAyMBCEBq0
uQgAKy/hggEAAAAAAAAAL089RUVZRSBESUdJVEFMIFNFQ1VSSVRZL09VPUZJUlNUIEFETUlOSVNU
UkFUSVZFIEdST1VQL0NOPVJFQ0lQSUVOVFMvQ049TU1BSUZGUkVUAAAAHgD6PwEAAAAVAAAAU3lz
dGVtIEFkbWluaXN0cmF0b3IAAAAAAgH7PwEAAAAeAAAAAAAAANynQMjAQhAatLkIACsv4YIBAAAA
AAAAAC4AAAADAP0/5AQAAAMAGUAAAAAAAwAaQAAAAAAeADBAAQAAAAoAAABNTUFJRkZSRVQAAAAe
ADFAAQAAAAoAAABNTUFJRkZSRVQAAAAeADhAAQAAAAoAAABNTUFJRkZSRVQAAAAeADlAAQAAAAIA
AAAuAAAAAwB2QP////8DAAlZAQAAAAsAh4EIIAYAAAAAAMAAAAAAAABGAAAAAA6FAAAAAAAAAwDr
gQggBgAAAAAAwAAAAAAAAEYAAAAAAYUAAAAAAAALAPCBCCAGAAAAAADAAAAAAAAARgAAAAADhQAA
AAAAAAMA+oEIIAYAAAAAAMAAAAAAAABGAAAAABCFAAAAAAAAAwABggggBgAAAAAAwAAAAAAAAEYA
AAAAGIUAAAAAAAALACCCCCAGAAAAAADAAAAAAAAARgAAAAAGhQAAAAAAAAsAIYIIIAYAAAAAAMAA
AAAAAABGAAAAAIKFAAAAAAAACwApAAAAAAALACMAAAAAAAMABhCtF5AOAwAHED4PAAADABAQAAAA
AAMAERABAAAAHgAIEAEAAABlAAAATVMwNi0wNDJSRUxBVEVESU5URVJORVRFWFBMT1JFUkNSQVNI
SVNFWFBMT0lUQUJMRURBVEU6QVVHVVNUMjIsMjAwNlNFVkVSSVRZOkhJR0hTWVNURU1TQUZGRUNU
RUQ6V0lORAAAAAACAX8AAQAAAEcAAAA8QTY0MUNFQUREQkFFQUU0Qzk2RkM1QkY4NTQ2OTUyNjgw
MTQ1M0EzMkBhdi1tYWlsMDEuY29ycC5pbnQtZWV5ZS5jb20+AACvVg=
------_=_NextPart_001_01C6C62A.6571501B--

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH