|
|
|
|
| |
Credit:
The information has been provided by ling & wushi of team509 .
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-09-038
|
| |
Vulnerable Systems:
* Microsoft Internet Explorer 8 and earlier
The specific flaw exists when repeatedly calling event handlers after adding nodes of an HTML document. When a specially crafted webpage is repeatedly rendered, memory is improperly reused after it has been freed. Due to the controllable nature of the web browser, this vulnerability can be exploited to remotely compromise a system running under the security context of the currently logged in user.
Patch Availability:
Microsoft has issued an update to correct this vulnerability. More details can be found at: http://www.microsoft.com/technet/security/bulletin/MS09-019.mspx
CVE Information:
CVE-2009-1530
Disclosure Timeline:
2009-01-26 - Vulnerability reported to vendor
2009-06-10 - Coordinated public release of advisory
|
|
|
|
|