Revision Date: | 2015-08-03 | Version: | 44 | Title: | FTP Server Response Parsing Memory Corruption Vulnerability | Description: | The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption. | Family: | windows | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2007-0217
| Platform(s): | Microsoft Windows 2000 Microsoft Windows Server 2003 Microsoft Windows XP
| Product(s): | Microsoft Internet Explorer
| Definition Synopsis | Server 2003-Gold (IE7) Microsoft Windows Server 2003 (x86) Gold is installed
AND Microsoft Internet Explorer 7 is installed
AND the version of mshtml.dll is less than 7.0.6000.16414
XP,SP1 (64-bit) and Server 2003, SP1 (IE7)
Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed
Microsoft Windows XP SP1 (64-bit) is installed
OR Microsoft Windows Server 2003 SP1 (x86) is installed
AND Microsoft Internet Explorer 7 is installed
AND the version of mshtml.dll is less than 7.0.6000.16414
IE 7 on Windows XP,SP2
Microsoft Windows XP SP2 or later is installed
AND Microsoft Internet Explorer 7 is installed
AND the version of mshtml.dll is less than 7.0.6000.16414
Server 2003-Gold
Microsoft Windows Server 2003 (x86) Gold is installed
AND Microsoft Internet Explorer 6 is installed
AND the version of mshtml.dll is less than 6.0.3790.630
XP,SP1 (64-bit) and Server 2003, SP1 (IE6)
Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed
Microsoft Windows XP SP1 (64-bit) is installed
OR Microsoft Windows Server 2003 SP1 (x86) is installed
AND Microsoft Internet Explorer 6 is installed
AND the version of mshtml.dll is less than 6.0.3790.2858
IE 6 on Windows XP,SP2
Microsoft Windows XP SP2 or later is installed
AND Microsoft Internet Explorer 6 is installed
AND the version of mshtml.dll is less than 6.0.2900.3059
IE 6 on Windows 2000
Microsoft Windows 2000 SP4 or later is installed
AND Microsoft Internet Explorer 6 is installed
AND the version of mshtml.dll is less than 6.0.2800.1589
IE 5.01,SP4 on Win2k,SP4
Microsoft Windows 2000 SP4 or later is installed
AND Microsoft Internet Explorer 5.01 SP4 is installed
AND the version of mshtml.dll is less than 5.0.3849.500
|
|