Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:IE:MHTML-REDIR-INFO

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Microsoft Internet Explorer MHTML Redirect Information Disclosure

Release Date

2008/08/12

Update Number

1252

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Microsoft Internet Explorer MHTML Redirect Information Disclosure


This signature detects an MHTML redirect specially crafted to exploit a known vulnerability in Internet Explorer. An attacker who successfully exploited this could read data from another Internet Explorer domain or the local computer.

Extended Description

Microsoft Outlook Express And Windows Mail are prone to an information-disclosure vulnerability because of an error in the Windows MHTML protocol handler. Note that an attacker can exploit this issue via Internet Explorer because the browser internally uses the vulnerable component of Outlook Express and Windows Mail. Successful exploits will allow the attacker to bypass Internet Explorer domain restrictions and to read data from a different Internet Explorer domain or security zone.

Affected Products

  • HP Storage Management Appliance 2.1
  • HP Storage Management Appliance I
  • HP Storage Management Appliance II
  • HP Storage Management Appliance III
  • Microsoft Outlook Express 5.5 SP2
  • Microsoft Outlook Express 6.0
  • Microsoft Outlook Express 6.0 SP1
  • Microsoft Windows 2000 Professional SP4
  • Microsoft Windows Mail
  • Microsoft Windows Server 2003 SP1
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Server 2003 Itanium SP1
  • Microsoft Windows Server 2003 Itanium SP2
  • Microsoft Windows Server 2003 Standard x64 Edition
  • Microsoft Windows Server 2003 x64 SP2
  • Microsoft Windows Server 2008 for 32-bit Systems
  • Microsoft Windows Server 2008 for Itanium-based Systems
  • Microsoft Windows Server 2008 for x64-based Systems
  • Microsoft Windows Vista SP1
  • Microsoft Windows Vista
  • Microsoft Windows Vista x64 Edition SP1
  • Microsoft Windows Vista x64 Edition
  • Microsoft Windows XP Professional SP2
  • Microsoft Windows XP Professional SP3
  • Microsoft Windows XP Professional x64 Edition SP2
  • Microsoft Windows XP Professional x64 Edition

References

  • CVE: CVE-2008-1448
  • URL: http://www.microsoft.com/technet/security/Bulletin/MS08-048.mspx

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out