Oval Definition:oval:org.mitre.oval:def:353
Revision Date:2014-02-24Version:44
Title:IE v5.01,SP4 Function Pointer Override Cross Domain Vulnerability
Description:Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-0815
Platform(s):Microsoft Windows 2000
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Software section
  • Internet Explorer 5.01 Service Pack 4 is installed
  • AND the version of mshtml.dll is less than 5.0.3810.1700
  • AND NOT the patch q824145 is installed (Installed Components key)
  • AND Configuration section
  • ActiveX controls and active scripting are enabled
  • current user settings are being used and ActiveX controls and active scripting are enabled
  • NOT use machine settings rather than individual user settings
  • AND ActiveX controls are enabled for the current user
  • AND active scripting is enabled for the current user
  • OR local machine settings are being used and ActiveX controls and active scripting are enabled
  • use machine settings rather than individual user settings
  • AND ActiveX controls are enabled for the local machine
  • AND active scripting is enabled for the local machine
  • BACK