Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
BID:10318
Info
Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
| Bugtraq ID: | 10318 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2004 12:00AM |
| Updated: | May 10 2004 12:00AM |
| Credit: | Discovery of this issue is credited to "Rafel Ivgi, The-Insider" <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
Internet Explorer is reportedly affected by a XML parsing denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed XML tags.
Successful exploitation of this issue might allow a remote attacker to crash a vulnerable web browser.
Internet Explorer is reportedly affected by a XML parsing denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed XML tags.
Successful exploitation of this issue might allow a remote attacker to crash a vulnerable web browser.
Exploit / POC
Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
No exploit is required to leverage this issue. The following XML tag is reportedly sufficient to leverage this issue:
<Ref href = "&"/>
No exploit is required to leverage this issue. The following XML tag is reportedly sufficient to leverage this issue:
<Ref href = "&"/>
Solution / Fix
Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
References:
References:
- Vendor Home Page (Microsoft)
- msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh ("Rafel Ivgi, The-Insider"
)