Products  |  Software  |  Services  |  Solutions  |  Support  |  Supplies  
My OcéContact Océ
US-CERT TA04-184A: Internet Explorer Update to
Disable ADODB.Stream ActiveX Control
/NR/rdonlyres/eor7ve7hxwkjdk43iidczzspz7rvxd6voteqfszflsvbsgseb3hwlndaikano6gyn3hiepyemwt46d/_TemplateResource1.gif
 
A class of vulnerabilities in IE allows malicious script from one domain to
execute in a different domain which may also be in a different IE security
zone.
 
By convincing a victim to view an HTML document (web page, HTML email),
an attacker could execute script in a different security domain than the one
containing the attacker's document. By causing script to be run in the Local
Machine Zone, the attacker could execute arbitrary code with the privileges
of the user running IE.
 
Recent incident activity known as Download.Ject (also JS.Scob.Trojan, Scob,
JS.Toofeer) uses cross-domain vulnerabilities and the ADODB.Stream control
to install software that steals sensitive financial information
 
Océ systems Vulnerability Recommended action
Océ TDS300 1.x
Océ TDS400 1.x 2.x
Océ TDS600 3.x 4.x
Océ TDS800 1.x 2.x
Océ TCS400 2.x
Not vulnerable None
Océ DPS400
Océ VP2105
Not vulnerable None
Océ VP2090
Not vulnerable None
Océ VP3090
Not vulnerable None
Océ 900C
Not vulnerable None
Océ 950C Vulnerable Download and install patch from Microsoft site
Océ 910C
Océ 960C
Océ 1000C
 
These systems may be infected by this security issue Automatic System Update
Océ Corporate Site
  Home | Products | Software | Services | Solutions | Support | Supplies  
Privacy policy | Terms of use | Other Océ websites »
© 2008 Océ
All rights reserved