RE: [Full-Disclosure] New Microsoft Internet Explorer mshtml.dll Denial of Service?

From: Steve Wray (steve.wray_at_paradise.net.nz)
Date: 09/02/03

  • Next message: Daniel Tams: "Re: [Full-Disclosure] JAP back doored"
    To: "'Marc Ruef'" <maru@scip.ch>, <full-disclosure@lists.netsys.com>
    Date: Wed, 3 Sep 2003 08:04:36 +1200
    
    

    Ok I went there and no crash!
    :)
    Heres the html that I created to test the principal as
    well.

    My MSIE is 6.0.2800.1106.xpsp2.030422-1633

    I only experience the crash when clicking in Outlook 2002.

    [snip]
    > > Its a mail client issue; doesn't happen if you click on
    > > a link from Internet Explorer.
    >
    > No, I am very sure that this happens also, if you follow the
    > link inside
    > a web page only (without an involving mail client).
    >
    > So go to http://www.counterpane.com/crypto-gram.html , scroll down and
    > click the link that says "Holger Hasselbach has translated several
    > issues of Crypto-Gram into German [...]". The error occurs as
    > described
    > in my original posting.
    >
    > > Your mail headers don't exactly give away your own mail client.
    > > What would it be?
    >
    > Microsoft Outlook 2002 SP2 on Windows XP Professional
    >
    > Yours,
    >
    > Marc Ruef

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Daniel Tams: "Re: [Full-Disclosure] JAP back doored"

    Relevant Pages

    • Re:
      ... > I have created an order form that users javascript to create a new html ... > document when the customers clicks the "print page" button. ... My testing in Firefox 1.5 seems to indicate that window.print is ... pretty obvious that no matter what, it shouldn't be able to crash the ...
      (comp.lang.javascript)
    • IE Immediately Crashes When Loading A HTML Page From A CD/DVD
      ... The CSS files just reference the images ... When I load index.html from my hard drive, IE displays the page fine, ... the Autorun.inf and HTML directory to a CD (using either Nero or the ... before you even see anything of the page, IE will crash. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Best Web browser for OS 9.2.1?
      ... But unfortunately this browser leaks a lot of incompatibilities in many, ... If you install any version of MSIE and wants to control your system using a speech system, such as Apple TTS+SR or IBM ViaVoice, any MSIE version will crash for good, if you don't regualrely clean up the cache file, - and it isn't enough to do it through the browser, but you have to do this jmanually. ... If MSIE 5.x was open, and I called ClarisEmailer, MSIE crashed 19 out of 20 times with the result that sometimes I also lost mail in ClarisEmailer. ...
      (comp.sys.mac.apps)
    • Re: MS Pocket IE team or Jay McLain: can you help?
      ... > This seems to be a bug with Html View in Pocket PC 2003 because I can ... The problem is with sending HTML to a Html ... As soon as DTM_ENDOFSOURCE is sent, the control ... > stable with less crash. ...
      (microsoft.public.pocketpc.developer)
    • Re: FireFox bugged isolated
      ... you're saying if someone wrote some malicious HTML that will cause ... > Firefox to freeze or crash then no part of Firefox's code can be blamed? ... for Microsoft trying to change HTML into crap and then using illegal methods ...
      (uk.people.consumers.ebay)