Oval Definition:
oval:org.mitre.oval:def:3926
Revision Date
:
2014-02-24
Version
:
45
Title
:
IE6,SP1 Content Advisor Memory Corruption Vulnerability
Description
:
Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2005-0555
Platform(s)
:
Microsoft Windows 2000
Microsoft Windows XP
Product(s)
:
Microsoft Internet Explorer
Definition Synopsis
Software section
Internet Explorer 6 Service Pack 1 is installed
AND
a vulnerable version of mshtml.dll exisits GDR/QFE
machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498
OR
machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499
AND
NOT
the patch kb890923 is installed (XP Win2K Hotfix key)
AND
Configuration section
ActiveX controls and active scripting are enabled
current user settings are being used and ActiveX controls and active scripting are enabled
NOT
use machine settings rather than individual user settings
AND
ActiveX controls are enabled for the current user
AND
active scripting is enabled for the current user
OR
local machine settings are being used and ActiveX controls and active scripting are enabled
use machine settings rather than individual user settings
AND
ActiveX controls are enabled for the local machine
AND
active scripting is enabled for the local machine
BACK