Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:IE:IFRAME-FILE

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Internet Explorer "IFRAME" Tag Local File Source

Release Date

2005/03/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Internet Explorer "IFRAME" Tag Local File Source


This signature detects an HTML file containing an "IFRAME" tag with a source set that points to a location to a local file. Attackers can be attempting to open malware placed on the target system by a different exploit. Note: Network administrators can use this technique for legitimate purposes.

Extended Description

Microsoft Internet Explorer is reported prone to a remote buffer overflow vulnerability. This issue presents itself due to insufficient boundary checks performed by the application and results in arbitrary code execution or a denial of service. This issue does not affect the following Internet Explorer 6 versions: - Internet Explorer 6 for Windows Server 2003 - Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003 - Internet Explorer 6 for Windows XP Service Pack 2

Affected Products

  • Avaya DefinityOne Media Servers R10
  • Avaya DefinityOne Media Servers R11
  • Avaya DefinityOne Media Servers R12
  • Avaya DefinityOne Media Servers R6
  • Avaya DefinityOne Media Servers R7
  • Avaya DefinityOne Media Servers R8
  • Avaya DefinityOne Media Servers R9
  • Avaya DefinityOne Media Servers
  • Avaya IP600 Media Servers R10
  • Avaya IP600 Media Servers R11
  • Avaya IP600 Media Servers R12
  • Avaya IP600 Media Servers R6
  • Avaya IP600 Media Servers R7
  • Avaya IP600 Media Servers R8
  • Avaya IP600 Media Servers R9
  • Avaya IP600 Media Servers
  • Avaya Modular Messaging S3400
  • Avaya S3400 Message Application Server
  • Avaya S8100 Media Servers R10
  • Avaya S8100 Media Servers R11
  • Avaya S8100 Media Servers R12
  • Avaya S8100 Media Servers R6
  • Avaya S8100 Media Servers R7
  • Avaya S8100 Media Servers R8
  • Avaya S8100 Media Servers R9
  • Avaya S8100 Media Servers
  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 6.0 SP1

References

  • BugTraq: 11515
  • CVE: CVE-2004-1050
  • URL: http://www.microsoft.com/technet/security/bulletin/ms04-040.mspx

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out