Update Protection against Vector Markup Language (VML) Vulnerability (MS06-055)
| Check Point Reference: | CPAI-2006-128 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Advisory (925568) Microsoft Security Bulletin MS06-055 |
|
| Industry Reference(s): | CVE-2006-4868 US-CERT VU#416092 |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Internet Explorer 5.01 SP4 on Microsoft Windows 2000 SP4 Microsoft Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4 Microsoft Internet Explorer 6 SP1 on Microsoft Windows XP SP1 Microsoft Internet Explorer 6 for Microsoft Windows XP SP2 Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 SP1 Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 (Itanium) Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 with SP1 (Itanium) Microsoft Internet Explorer 6 for Microsoft Windows Server 2003 x64 Edition Microsoft Internet Explorer 6 for Microsoft Windows XP Professional x64 Edition Microsoft Internet Explorer 6 SP1 on Microsoft Windows 98 Microsoft Internet Explorer 6 SP1 on Microsoft Windows 98 SE Microsoft Internet Explorer 6 SP1 on Microsoft Windows Millennium Edition | ||
| Vulnerability Description Microsoft Internet Explorer (IE) contains a heap overflow vulnerability. The vulnerability exists in Microsoft Vector Graphics Rendering library. The application fails to properly handle malformed Vector Markup Language (VML) tags. VML is a set of XML tags for drawing vector graphics. By convincing a user to visit a specially crafted Web page, a remote attacker may trigger this vulnerability to deny service from legitimate users (by causing the victim's Web browser to crash) or execute arbitrary code on an affected system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS06-055 |
|
|
Vulnerability Details The vulnerability occurs in the Microsoft Vector Graphics Rendering library when browsing a specially crafted VML document with an overly long 'fill' parameter within a 'rect' tag. An attacker can trigger this flaw by convincing a user to view a specially crafted HTML document. Successful exploitation could result in the crashing of the victim's Web browser, once the malicious page is loaded allowing execution of arbitrary code. |
Protection Overview
The update protects against this vulnerability by blocking the vulnerable COM object. Depending on the traffic mix, activating this protection may result in performance degradation.
Please note that the protection offered in this advisory may cause false positives by blocking legitimate traffic. We are working on solving this issue.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on November 13, 2006 includes the following protections:
OpenSSL RSA Key Signature Forgery Vulnerability (CPAI-2006-123)
C-News File Inclusion Vulnerability (CPAI-2006-125)
phpFullAnnu File Inclusion Vulnerability (CPAI-2006-126)
Microsoft setSlice Integer Overflow Vulnerability (MS06-057) - CPAI-2006-127
Microsoft Vector Markup Language (VML) Vulnerability (MS06-055) - CPAI-2006-128
Microsoft Server Service Vulnerabilities (MS06-063) – CPAI-32006-129
Multiple MySQL Query Commands Vulnerabilities (CPAI-2006-130)
W-Agora Remote File Inclusion Vulnerabilities (CPAI-2006-131)
Protecting against Heap Spraying Techniques by Blocking Known Shell Code Exploits (SBP-2006-12)