Microsoft Internet Explorer on Windows XP Fails to Restrict Drag and Drop Operations When Configured to Disable These Operations
|
|
SecurityTracker Alert ID: 1011859
|
|
SecurityTracker URL: http://securitytracker.com/id?1011859
|
|
CVE Reference: CAN-2004-0979
(Links to External Site)
|
Date: Oct 21 2004
|
Impact: Modification of system information, Modification of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 6
|
Description: A vulnerability was reported in Microsoft Internet Explorer on Windows XP. The browser does not enforce the security preference for "Drag and drop or copy and paste files."
The vendor reported that when the "drag and drop or copy and paste files" setting is configured to 'disable' or 'prompt', the system will permit the operations anyway.
|
Impact: The system fails to restrict drag and drop operations when the feature is configured to disabled these operations.
|
Solution: The vendor issued a fix as part of MS04-038, described at:
http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx
For
Internet Explorer 6 on Windows XP:
http://www.microsoft.com/downloads/details.aspx?FamilyId=A89CFBE8-C299-415D-A9D6-7CC6429C547D&displaylang=en
For
Internet Explorer 6 for Windows XP Service Pack 1 (64-Bit Edition):
http://www.microsoft.com/downloads/details.aspx?FamilyId=C05103E8-4402-4D54-BA03-FBBC24142E4D&displ
aylang=en
Internet Explorer 6 for Windows XP Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=CF47B515-3F51-43E1-9246-2C2264C49E2E&displayla
ng=en
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms04-038.mspx (Links to External Site)
|
Cause: State error
|
Underlying OS: Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 21 Oct 2004 10:09:53 -0400
Subject: http://www.kb.cert.org/vuls/id/630720
|
CERT VU #630720
CVE: CAN-2004-0979
|
|