[NT] DoS in Multiple IE Versions (Self-Referenced Directives)
From: support@securiteam.comDate: 04/20/02
- Previous message: support@securiteam.com: "[NT] Snitz Forums 2000 Remote SQL Query Manipulation Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Sat, 20 Apr 2002 19:07:31 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
DoS in Multiple IE Versions (Self-Referenced Directives)
------------------------------------------------------------------------
SUMMARY
OBJECT elements are used for embedded OLE in HTML documents. A flaw in the
way Microsoft Internet Explorer processes this directive allows a page
that causes a loop in object dependency, or loads itself in a certain
manner in an OBJECT, to completely crash Internet Explorer.
DETAILS
Exploit:
To date, there have been discovered 4 points of exploitation to crash the
browser. Here is one example:
Creating a file called crash.htm with the following content:
---- <0BJECT DATA="CRASH.HTM" TYPE="text/html"></OBJECT> ---- (NOTE: The O letter has been replaced with a 0)Internet Explorer dies inside shdocvw.dll with a call stack overflow.
Workaround: Set "Run ActiveX Controls and Plugins" to disabled in ALL zones.
ADDITIONAL INFORMATION
The information has been provided by <mailto:mattmurphy@kc.rr.com> Matthew Murphy.
========================================
This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
==================== ====================
DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NT] Snitz Forums 2000 Remote SQL Query Manipulation Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|