60490 : Microsoft IE Layout STYLE Tag getElementsByTagName Method Handling Memory Corruption
Printer | http://osvdb.org/60490 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
6 751 over 2 years ago about 1 year ago 26 times 55%

This Entry needs help! It is only 55% Complete. Click the edit link above to add more information.

Contributing is fast and easy, and benefits the entire security community.

Timeline

Vendor Informed Date Vendor Ack Date Disclosure Date Exploit Publish Date Vendor Solution Date
2009-06-09 2009-06-09 2009-11-20 2009-11-20 2009-12-08
Time to Patch Days of Exposure
182 days 18 days

Description

<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3672" target="_blank">CVE</a>)</em> : Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method for the STYLE tag name, selection of the single element in the returned list, and a change to the outerHTML property of this element, related to Cascading Style Sheets (CSS) and mshtml.dll, aka &quot;HTML Object Memory Corruption Vulnerability.&quot; NOTE: some of these details are obtained from third party information. NOTE: this issue was originally assigned CVE-2009-4054, but Microsoft assigned a duplicate identifier of CVE-2009-3672. CVE consumers should use this identifier instead of CVE-2009-4054.

Classification

Location: Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: Vendor Verified, Coordinated Disclosure
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Unknown or Incomplete

References

Tools & Filters

43064

Credit

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2009-12-02 | Disagree? | There are 2 more: View All

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/12/09 18:15:24 | Microsoft Patch Tuesday: Critical Update for IE

from: NetworkWorld

...nCircle security expert, senior security engineer Tyler Reguly, agreed "Number one on everyone's hit list today should be MS09-072, the IE patch, as this includes a patch for the current IE 0-day vulnerability. Patching IE is always crucial but given the public...

2009/12/08 16:00:00 | Microsoft patches 12 bugs, including IE8-only flaws

from: NetworkWorld

...update. It trumps the bunch." Richie Lai, the director of vulnerability research at security company Qualys, echoed Storms. "MS09-072 affects IE, which is a big attack surface," said Lai, "and the vulnerabilities are primed to be exploited by classic drive-by...

2009/12/08 23:50:33 | Microsoft Patches Zero-Day Internet Explorer Hole

from: Information Week

...IE8 with its well known patching mechanism or Firefox 3 with its more aggressive patching schedule." Kandek observes that MS09-072 is the only bulletin this month that affects Windows 7 and Windows 2008 R2. After the Internet Explorer fix, Rapid7 security...

2009/12/09 10:15:57 | Microsoft issues six security patches

from: ComputerWeekly.com

...month particularly important for IT departments to shore-up patches and protect against web-borne malware threats," he said. MS09-072 is likely to have the greatest impact on end users as it affects all IT environments using Internet Explorer (6, 7 and 8),...

2009/12/08 20:45:41 | Microsoft Fixes IE Zero-Day Flaw

from: PC World

...critical for IE 7 on Server 2003 and Server 2008, as well as IE 8 on Server 2003 and Server 2008. For more details see the MS09-072 bulletin. A second bulletin addresses flaws in Microsoft Office Project that could be triggered by opening a malicious Project...

2009/12/10 18:38:40 | Microsoft knew of just-patched IE zero-day for months

from: NetworkWorld

...that Microsoft had known of the flaw for longer than two weeks, however. It credited iDefense with reporting the bug in the MS09-072 security bulletin that included the IE6 and IE7 patch, a fact Storms noticed. On Wednesday, Storms pointed out the iDefense...

2009/12/09 13:06:02 | Five Critical Patches Issued for Internet Explorer

from: Sci-Tech Today

...patches that need to be addressed this month, the big so-what for Microsoft patches centers around the ubiquitous MS09-072 affecting all versions of Internet Explorer and carrying Microsoft's highest exploitability rating, said Paul Zimski, vice president...

2009/12/09 16:00:00 | Microsoft getting better at Patch Tuesday updates, experts say

from: NetworkWorld

...security advisory, and before the day was done issued a second update to report a patch would be developed. That patch, MS09-072, was delivered Tuesday as part of the regular patching cycle. "You have advisories, you have re-releases that they are announcing...

2009/12/09 13:56:35 | Firms urged to apply Microsoft and Adobe patches

from: VNUNet.com

...Walker, regional director UK and Ireland at security solutions provider Lumension, said: "Of the three critical patches, MS09-072 is the most ubiquitous, affecting all versions of Internet Explorer and carrying Microsoft's highest exploitability rating. This,...

2009/12/08 17:40:25 | Microsoft patch batch includes fix for zero-day IE flaw

from: SC Magazine

...five of which are present in Internet Explorer (IE) and comprise the most pressing patch to deploy. That bulletin -- MS09-072 -- is the only patch that carries both a "critical" severity rating and Exploitability Index grade of 1, meaning consistent exploit...

2009/12/09 11:23:30 | Last patch train of the decade rolls in from Redmond

from: The Register

...bulletins - three rated "critical" and three classified as "important" - tackling 12 security vulns. The critical IE patch (MS09-072) addressed five vulnerabilities, including a zero-day bug that had become the target of hacking attacks. The other two critical...

2009/12/10 07:20:32 | Final patch Tuesday of 2009 from Microsoft sees Internet Explorer zero-day vulnerability covered

from: SC Magazine

...throughout their organisation.” Finally, Jason Miller, security and data team manager at Shavlik Technologies, said: “MS09-072 is the first security bulletin administrators should address on their network. With this bulletin, the advisory expires if administrators...

2009/12/08 20:50:02 | Patch Tuesday: Microsoft plugs IE 'drive-by download' security holes

from: ZDNet

...updates appropriately. Attacker hosts a malicious webpage, lures victim to it. Public exploit code already exists for CVE-2009-3672 affecting IE6 and IE7. We expect to see exploits for other vulnerabilities that affect other IE versions within 30 days. ...

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use