Microsoft
IE Request Header Cross Domain Information Disclosure Vulnerability
Date Discovered:
06/10/2008
Severity:
High
Operating Systems
Affected:
Microsoft Windows 2000
SP4
Microsoft Windows XP SP2
Microsoft Windows XP SP3
Microsoft Windows XP Professional x64
Microsoft Windows XP Professional x64 SP2
Microsoft Windows Server 2003 SP1
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64
Microsoft Windows Server 2003 x64 SP2
Applications Affected:
Microsoft Internet
Explorer 5.01 SP4
Microsoft Internet Explorer 6 SP1
Microsoft Internet Explorer 6
Microsoft Windows Internet Explorer 7
Synopsis
Microsoft
Internet Explorer is prone to a information disclosure vulnerability
because Microsoft Internet Explorer does not correctly handle certain
request headers.
An
information disclosure vulnerability exists in the way Internet
Explorer handles certain request headers. An attacker could exploit the
vulnerability by constructing a specially crafted Web page. When a user
views the Web page, the vulnerability could allow the attacker to read
data from another Internet Explorer domain.
Internet Explorer incorrectly parses a specially crafted request
header, allowing a violation of the same origin policy. An attacker who
successfully exploited this vulnerability could read data from another
domain in Internet Explorer.
“iPolicy is one of the most visionary firewall vendors in the firewall Magic Quadrant. Its architecture of a central session processing engine and multiple content blades that are able to block based on signatures, rules and so on is the closest to the network security ideal.”
Greg Young, John Pescatore
Magic Quadrant for Network Firewalls, 2H04, Gartner