Oval Definition:
oval:org.mitre.oval:def:5820
Revision Date
:
2014-08-18
Version
:
46
Title
:
HTML Object Memory Corruption Vulnerability
Description
:
Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2008-2254
Platform(s)
:
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s)
:
Microsoft Internet Explorer
Definition Synopsis
Win 2K + IE6 vulnerable version
Microsoft Windows 2000 is installed
AND
Microsoft Internet Explorer 6 is installed
AND
Mshtml.dll version is less than 6.0.2800.1613
OR
Win XP + IE 6
Microsoft Windows XP is installed
AND
Mshtml.dll version is less than 6.0.2900.3395
OR
Win XP + IE 6
Microsoft Windows XP (32-bit) is installed
AND
Mshtml.dll version is less than 6.0.2900.5626
OR
Win XP / Win 2K3 + IE 7
Microsoft Internet Explorer 7 is installed
AND
Win XP / Win 2K3
Microsoft Windows XP is installed
OR
Microsoft Windows Server 2003 (32-bit) is installed
OR
Microsoft Windows Server 2003 (x64) is installed
OR
Microsoft Windows Server 2003 (ia64) Gold is installed
AND
Check for LDR / GDR
Mshtml.dll version is less than 7.0.6000.16705
OR
Check for LDR
Mshtml.dll version is greater than 7.0.6000.20000
AND
Check if the version mshtml.dll is less than 7.0.6000.20861
OR
Win 2K3 / Win XP X64 and IE 6
Microsoft Internet Explorer 6 is installed
AND
Mshtml.dll version is less than 6.0.3790.3167
AND
Win 2K3 / Win XP X64
Microsoft Windows Server 2003 (32-bit) is installed
OR
Microsoft Windows Server 2003 (ia64) Gold is installed
OR
Microsoft Windows Server 2003 (x64) is installed
OR
Microsoft Windows XP x64 is installed
OR
Win XP X64 / Win 2K3
Microsoft Internet Explorer 6 is installed
AND
Mshtml.dll version is less than 6.0.3790.4324
AND
Win 2K3 / Win XP X64
Microsoft Windows Server 2003 (32-bit) is installed
OR
Microsoft Windows Server 2003 (x64) is installed
OR
Microsoft Windows Server 2003 (ia64) Gold is installed
OR
Microsoft Windows XP x64 is installed
OR
Win Vista and IE7
Microsoft Windows Vista is installed
AND
Check for LDR and GDR
Mshtml.dll version is less than 7.0.6000.16711
OR
Check for LDR
Mshtml.dll version is greater than 7.0.6000.20000
AND
Check if the version of mshtml.dll is less than 7.0.6000.20868
AND
Microsoft Internet Explorer 7 is installed
OR
Win Vista / Win 2K8 and IE7
Microsoft Internet Explorer 7 is installed
AND
Win Vista/ Win 2K8
Microsoft Windows Vista (32-bit) is installed
OR
Microsoft Windows Vista x64 Edition is installed
OR
Microsoft Windows Server 2008 (32-bit) is installed
OR
Microsoft Windows Server 2008 (64-bit) is installed
OR
Microsoft Windows Server 2008 (ia-64) is installed
AND
Check for LDR /GDR
Mshtml.dll version is less than 7.0.6001.18099
OR
Check for LDR
Mshtml.dll version is greater than or equal to 7.0.6001.22000
AND
Check if the version of mshtml.dll is less than 7.0.6001.22212
BACK