SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#431576

Microsoft Internet Explorer vulnerable to address bar spoofing on double byte character set systems

Overview

Microsoft Internet Explorer contains a vulnerability in how it processes URLs on Double Byte Character Set (DBCS) systems. This could allow an attacker to spoof the address of a web site.

I. Description

Microsoft Internet Explorer contains a canonicalization error when it parses special characters in a URL on a DBCS system. A DBCS system represents characters with either a single byte or a double byte code. DBCS is used with some Asian versions of Microsoft Windows. Because of the error in how IE parses URLs on DBCS systems, a web site operator could make it appear that the content from his or her web site actually originated from another site.

II. Impact

By making a malicious web site appear to be a site that the user trusts, an attacker could convince the user to provide sensitive information.

III. Solution

Apply a patch

Apply the patch referenced in MS04-038.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable13-Oct-2004

References


http://www.microsoft.com/technet/security/bulletin/MS04-038.mspx
http://securitytracker.com/alerts/2004/Oct/1011643.html

Credit

Thanks to Microsoft for reporting this vulnerability.

This document was written by Will Dormann, based on the information provided in the Microsoft Security Bulletin.

Other Information

Date Public10/12/2004
Date First Published10/13/2004 05:42:00 PM
Date Last Updated10/18/2004
CERT Advisory 
CVE-ID(s)CAN-2004-0844
NVD-ID(s)CAN-2004-0844
US-CERT Technical Alerts 
Metric1.98
Document Revision7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader