Crash in Internet Explorer 6.0 Sp1

From: David F. Madrid (conde0_at_TELEFONICA.NET)
Date: 05/05/03

  • Next message: -= Jimmino =-: "For the FRENCH Community [Advisories Fr]"
    Date:         Mon, 5 May 2003 18:39:22 -0300
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Affected product : IE 6.0 Sp1

    Vendor Status : the issue will be solved in the next service pack

    Description :

    Internet explorer can be crashed by clicking on a specially crafted link .
    The problem is in the AnchorClick DHTML behaviour of the A ( link )
    object . With this behaviour you can specify a Folder instead of using the
    href attribute . If you leave this field blank , upon clicking on the link
    internet explorer will crash with an access violation when trying to write
    to a null pointer . You can test this issue by clicking the link on this
    page

    http://usuarios.lycos.es/actualidad21/ie_URL_behaviour.html

    --
    Regards ,
    David F. Madrid
    Madrid , Spain
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Delivery co-sponsored by IP3 Inc.
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    SECURITY QUESTIONS? We've got answers...Apply for a scholarship and become
    TICSA certified.
    Do not miss your opportunity to discover solutions to what our participants
    have identified as their top 5 IT Security Challenges. You will return to
    work better prepared to put into place an effective security strategy
    utilizing the latest security tools, bookmarks and URL's.
    <http://www.ip3seminars.com>
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    

  • Next message: -= Jimmino =-: "For the FRENCH Community [Advisories Fr]"

    Relevant Pages

    • Crash in Internet Explorer 6.0 Sp1
      ... the issue will be solved in the next service pack ... Internet explorer can be crashed by clicking on a specially crafted link. ... The problem is in the AnchorClick DHTML behaviour of the A ... Madrid, Spain ...
      (Bugtraq)
    • [NT] Microsoft Agent Remote Code Execution (MS07-020)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Outlook Express open HTML e-mail messages in the Restricted sites zone. ... section for more information about Internet Explorer Enhanced Security ...
      (Securiteam)
    • [NT] Vulnerability in Microsoft Agent Allows Code Execution (MS06-068)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... for more information about Internet Explorer Enhanced Security ... Configure Internet Explorer to prompt before running ActiveX Controls ...
      (Securiteam)
    • [NT] Vulnerability in Microsofts HTML Converter Could Allow Code Execution
      ... Beyond Security in Canada ... to promote the most advanced vulnerability assessment solutions today. ... Internet Explorer on Windows Server 2003 runs in Enhanced ... all intranet Web sites and all Universal Naming Convention paths ...
      (Securiteam)
    • [NT] Vulnerability in Visual Studio 2005 Could Allow Remote Code Execution (MS06-073)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... allow-list for ActiveX controls in Internet Explorer 7. ...
      (Securiteam)