Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
BID:10552
Info
Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
| Bugtraq ID: | 10552 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2004 12:00AM |
| Updated: | Jun 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Rafel Ivgi" <[email protected]>, further research performed by "Berend-Jan Wever" <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
A vulnerability is reported to exist in Internet Explorer that may allow an attacker to cause the application to crash. The issue presents itself when a user attempts to invoke the "Save As" option on a malicious HREF URI.
When this URI is processed the issue leads to a crash in the running instance of Internet Explorer and all windows spawned from this instance.
A vulnerability is reported to exist in Internet Explorer that may allow an attacker to cause the application to crash. The issue presents itself when a user attempts to invoke the "Save As" option on a malicious HREF URI.
When this URI is processed the issue leads to a crash in the running instance of Internet Explorer and all windows spawned from this instance.
Exploit / POC
Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
The following example is avilable:
<center><a href=::%7b>Right Click aOn Me And Click "Save Target As"</a>
The following example is avilable:
<center><a href=::%7b>Right Click aOn Me And Click "Save Target As"</a>
Solution / Fix
Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
References:
References:
- Technet Security (Microsoft)
- RE: Internet Explorer Remote Null Pointer Crash(mshtml.dll) ("Thor Larholm"
) - Re: Internet Explorer Remote Null Pointer Crash(mshtml.dll) ("Berend-Jan Wever"
)