Short Name |
HTTP:STC:IE:CVE-2008-2256-MC
|
Severity |
High
|
Recommended |
No
|
Recommended Action |
Drop Packet
|
Category |
HTTP
|
Keywords |
Microsoft Internet Explorer Uninitialized Memory Corruption (CVE-2008-2256)
|
Release Date |
2008/08/12
|
Update Number |
1252
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: Microsoft Internet Explorer Uninitialized Memory Corruption (CVE-2008-2256)
This signature detects invalid HTTP responses. Internet Explorer versions 7.0 and earlier are vulnerable to a double-free error when processing malformed HTTP responses. A successful attack can result in arbitrary code execution.
Extended Description
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability that occurs when the application tries to parse a specially crafted web page.
Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user.
Affected Products
- Avaya Messaging Application Server MM 1.1
- Avaya Messaging Application Server MM 2.0
- Avaya Messaging Application Server MM 3.0
- Avaya Messaging Application Server MM 3.1
- Avaya Messaging Application Server
- HP Storage Management Appliance 2.1
- HP Storage Management Appliance I
- HP Storage Management Appliance II
- HP Storage Management Appliance III
- Microsoft Internet Explorer 5.0.1
- Microsoft Internet Explorer 5.0.1 SP1
- Microsoft Internet Explorer 5.0.1 SP2
- Microsoft Internet Explorer 5.0.1 SP3
- Microsoft Internet Explorer 5.0.1 SP4
- Microsoft Internet Explorer 6.0
- Microsoft Internet Explorer 6.0 SP1
- Microsoft Internet Explorer 7.0
- Nortel Networks CallPilot 1002Rp
- Nortel Networks CallPilot 200I
- Nortel Networks CallPilot 201I
- Nortel Networks CallPilot 702T
- Nortel Networks CallPilot 703T
- Nortel Networks Contact Center
- Nortel Networks Contact Center Administration
- Nortel Networks Contact Center Express
- Nortel Networks Contact Center Manager
- Nortel Networks Contact Center Manager Server
- Nortel Networks Contact Center NCC
- Nortel Networks Enterprise VoIP TM-CS1000
- Nortel Networks Self-Service
- Nortel Networks Self-Service MPS 100
- Nortel Networks Self-Service MPS 1000
- Nortel Networks Self-Service MPS 500
- Nortel Networks Self-Service Peri Application
- Nortel Networks Self-Service Peri Workstation
- Nortel Networks Self-Service Speech Server
References