Overview
Setting the Internet Explorer 7 option DisableCachingOfSSLPages may not prevent the caching of SSL-enabled web pages.
Description
Administrators and users can set the Internet Explorer DisableCachingOfSSLPages option to prevent sensitive or private data from being saved to disk. The registry key for this setting is: HKCU\Software\Microsoft\Windows\CurrentVersion\InternetSettings\DisableCachingOfSSLPages |
Impact
Private or sensitive data may be written to disk inadvertently. |
Solution
We are currently unaware of a practical solution to this problem. |
Secure deletion |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://technet2.microsoft.com/windowsserver/en/library/c07587ec-4a60-4bca-8508-29a4296b72121033.mspx?mfr=true
- http://technet.microsoft.com/en-us/sysinternals/bb897443.aspx
- http://technet2.microsoft.com/WindowsVista/en/library/58358421-a7f5-4c97-ab41-2bcc61a58a701033.mspx?mfr=true
- http://blogs.msdn.com/ie/archive/2006/02/09/528963.aspx
- http://en.wikipedia.org/wiki/Comparison_of_disk_encryption_software
Acknowledgements
Thanks to Bill KNox from MITRE for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 2.40 |
Date Public: | 2008-05-09 |
Date First Published: | 2008-05-09 |
Date Last Updated: | 2008-05-09 18:17 UTC |
Document Revision: | 18 |