devz3ro.com
September 09 2010 07:42:32

Navigation

Users Online

· Guests Online: 1

· Members Online: 0

· Total Members: 190
· Newest Member: kompa

MS Windows Internet Explorer vector markup language buffer overflow vulnerability

· devz3ro on September 27 2006 07:33:42
Security






Allison Henry, IST–IS

There is a vulnerability in Microsoft Internet Explorer that can be exploited by an attacker to execute arbitrary code on the target system. Systems can become exploited when browsing to web pages infected with the malicious code. These infected web pages are now becoming more widespread, and in response, SNS is advising all campus users to take measures to mitigate this threat. There is no patch available for this vulnerability yet, but the following actions can be taken to reduce the risk to your systems (for a layered approach take as many of these actions as is appropriate in your environment):

* Make sure all systems are running antivirus software with current definitions and auto-update enabled.

* Unregister the vulnerable dll: Click "Start", click "Run", type: regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll" and then click "OK" (highly recommended, but may cause problems viewing the few websites that render VML).

* Configure IE6 for Windows XP SP2 to disable Binary and Script behaviors (check Microsoft's advisory page microsoft.com/technet for details on how to do this).

* Use an alternate web browser until a patch is issued by Microsoft.

* Configure your email client to display mail as plain text rather than HTML (an HTML email containing the malicious code can also be a vector).

* Use care when browsing — do not follow untrusted links sent via email or suspicious links from other sites (but do not rely on this for protection as previously safe sites could become infected with the malicious code).

More information about this vulnerability

* microsoft.com/technet
* symantec.com/enterprise

Comments

#1 | hyt on June 02 2010 23:08:13
I showed was not a CGI demo or concept .cheap wow gold The content was created in Adobe InDesign, buy wow gold as is the case for the print magazine, with the same designers adding interactive elements, tiffany This is a departure from the usual web model, unavoidably losing much of the visual context in the process. wow buy gold where a different team repurposes magazine content into HTML, com is not a re-purposed version of the magazine,cheapest wow gold Wired. but rather an separately-produced news service.We all know,cheapest wow gold and the seal blubber makes the screen all slippery

Post Comment

Please Login to Post a Comment.

Ratings

Rating is available to Members only.

Please login or register to vote.

No Ratings have been Posted.

Login

Username

Password



Not a member yet?
Click here to register.

Forgotten your password?
Request a new one here.

Shoutbox

You must login to post a message.

11/07/2009 22:08
question, how do you autoshuffle imeem tracks on myspace?

01/07/2009 23:59
i've been tryna get my imeem playlist to autoshuffle for the longest and nomatter what I do it wont. I tried what u said about getting the encoded link but it didn't work. Here's my imeem

27/01/2008 03:18
i found that if u leave the imeem tag on, click preview section and hit save teh second imeem appears itll save it. i have no i dea why, i got the tip from someone else. its currently working u might

26/01/2008 15:13
the new imeem work around isnt working it played a song for like 20sec then it refreshed and words BLOCK appeared in my profile eveytime it refreshed

01/06/2007 17:26
heres my imeem code for u to convert. thanks so much <object width="300" height="290"><param name="movie" value="http://media
.imee
m.com/pl/80Dd
TvK

13/05/2007 21:13
If you don't understand the code conversion for the imeem player, just register on this site and send me your original code in a PM. I will do the conversion for you.

25/02/2007 00:23
Isn't this site supposed to show up on myspace to see who's been spying on me? Can someone help me please? Thank's Linda

06/02/2007 19:11
wheres the tracker?

27/09/2006 07:26
Lrn2 Shoutbox, Kthnx.