[Japanese]
|
JVNDB-2010-000011
|
Internet Explorer information disclosure vulnerability
|
Internet Explorer contains an information disclosure vulnerability.
Internet Explorer contains an issue when handling content using specific encoding strings that may lead to an information disclosure vulnerability.
Daiki Fukumori of Cyber Defense Institute Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
|
|
Microsoft Corporation
- Microsoft Internet Explorer 7
- Microsoft Internet Explorer 6
- Microsoft Internet Explorer 5.01
|
|
When a user opens specially crafted web page, an attacker may be able to obtain sensitive information.
|
[Update the software]
Apply the update according to the information provided by the developer.
|
Microsoft Corporation
|
- Information Exposure(CWE-200) [IPA Evaluation]
|
- CVE-2010-0488
|
- JVN : JVN#49467403
- JVN Status Tracking Notes : JVNTR-2010-10
- National Vulnerability Database (NVD) : CVE-2010-0488
- IPA SECURITY ALERTS : 20100331-ms10-018 (Japanese)
- US-CERT Cyber Security Alerts : SA10-089A
- US-CERT Technical Cyber Security Alert : TA10-089A
- SecurityFocus : 39028
- SecurityTracker : 1023773
- VUPEN Security : VUPEN/ADV-2010-0744
|
- [2010/04/08]
Web page published
|