First published: Wed Nov 08 2006(Updated: )
Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =7.0 | |
=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5805 has a moderate severity level as it involves the mishandling of security certificates by Internet Explorer 7.
The fix for CVE-2006-5805 involves updating Microsoft Internet Explorer to a more recent and secure version.
CVE-2006-5805 specifically affects Microsoft Internet Explorer version 7.0 on Windows Vista.
Yes, CVE-2006-5805 can be exploited remotely by attackers to manipulate the display of security certificates.
Symptoms of CVE-2006-5805 exploitation include seeing an invalid security certificate warning for a legitimate secure website.