A low-risk stack overflow has been discovered in the .dll file responsible for parsing HTML. Any program such as Internet Explorer (IE), Outlook, and Outlook Express that uses mshtml.dll is vulnerable. This vulnerability is low risk because the overflow does not let intruders launch arbitrary commands but simply crash the affected program. DEMONSTRATION The following code was provided by Thor Larholm:
------------InstantCrash.html----------------- <iframe
id=test style="display:none"></iframe> ---------------------------------------------- VENDOR RESPONSE Microsoft was notified on December 4, 2000. According to Thor Larholm, Microsoft will address this bug in the next service pack for IE. CREDIT |
Stack Overflow Denial Of Service in Outlook, Internet Explorer and Outlook Express
0 comments
Hide comments