From security@greymagic.com Sat Aug 31 02:11:31 2002 From: GreyMagic Software To: Bugtraq Date: Fri, 23 Aug 2002 13:18:21 +0200 Subject: Accessing remote/local content in IE (GM#009-IE) [The following text is in the "iso-8859-1" character set] [Your display is set for the "US-ASCII" character set] [Some characters may be displayed incorrectly] GreyMagic Security Advisory GM#009-IE ===================================== By GreyMagic Software, Israel. 23 Aug 2002. Available in HTML format at http://security.greymagic.com/adv/gm009-ie/. Topic: Accessing remote/local content in IE. Discovery date: 18 Feb 2002. Affected applications: ====================== All tested versions of Microsoft Internet Explorer (IE5+); prior versions may be vulnerable as well. Note that any other application that uses Internet Explorer's engine (WebBrowser control) is affected as well (Outlook, MSN Explorer, etc.). Introduction: ============= Back in 1997, when Internet Explorer 4 was first released, XML was just starting to become popular. The popularity of XML prompted Microsoft to devise the early prototype of XML data-islands, using the Solution: ========= Microsoft was first informed on 18 Feb 2002, a patch was finally released on 22 Aug 2002 after a long investigation and testing period. The patch may be downloaded from: http://www.microsoft.com/technet/security/bulletin/ms02-047.asp. Tested on: ========== IE5 NT4, remote locations only. IE5.5 Win98, remote locations only. IE5.5 NT4, both remote and local locations. IE6 Win2000, remote locations only. IE6 WinXP, both remote and local locations. Demonstration: ============== A fully dynamic proof-of-concept demonstration of this issues is available at http://security.greymagic.com/adv/gm009-ie/. Feedback: ========= Please mail any questions or comments to security@greymagic.com. - Copyright © 2002 GreyMagic Software.