View Definition

Definition Id: oval:org.mitre.oval:def:6100 Version: 2  Last Modified: 2005-09-26
Title: IE v5.5,SP2 Install Engine Buffer Overflow
Description: Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.
Family: windows Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2004-0216
Platform(s): Microsoft Windows ME Product(s): Microsoft Internet Explorer
Definition Synopsis: