OSVDB ID: 30834

Title: Microsoft IE URLMON.DLL Long URL HTTP Redirect Overflow

Info

Disclosure

Aug 24, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Aug 08, 2006

Description

A remote buffer overflow exists in URLMON.DLL of Microsoft Internet Explorer. The browser fails to check the bounds on long URLs when using the HTTP 1.1 protocol and GZip compression resulting in a heap-based buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Disclosure: OSVDB Verified

Solution

Upgrade to version 7 or higher, as it has been reported to fix this vulnerability. Additionally, Microsoft has released a patch to address this issue, or users may opt to apply the following workaround: Disable the HTTP 1.1 protocol in Internet Explorer

Products

Microsoft Corporation

Internet Explorer

6
5

References

Credit

  • Derek Soeder - dsoedereeye.com - eEye Digital Security


Direct URL: http://osvdb.org/36218