积极预防 及时发现
快速响应 力保恢复
当类ID位于文件名后部时,Internet Explorer 5.5中的类型检查瑕疵不能显示类ID,...
发布时间:2001-09-20 信息来源:管理员

CNCVE编号:CNCVE-20010643 CVE编号:CAN-2001-0643 安全级别:中 漏洞中文描述: 当类ID位于文件名后部时,Internet Explorer 5.5中的类型检查瑕疵不能显示类ID,这将导致攻击者通过把危险的程序的文件类型转换为安全的文件类型从而欺骗用户执行。 漏洞英文描述: A type-check flaw in Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe type. 漏洞参考: Reference: BUGTRAQ:20010416 Double clicking on innocent looking files may be dangerous Reference: URL:http://www.securityfocus.com/archive/1/176909 Reference: MISC:http://vil.nai.com/vil/virusSummary.asp?virus_k=99048 Reference: MISC:http://www.s 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误