Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
BID:11536
Info
Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
| Bugtraq ID: | 11536 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Jehiah Czebotar <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
Microsoft Internet Explorer is reported prone to a remote denial of service vulnerability.
The issue presents itself due to a malfunction that occurs when certain font tags are encountered and rendered.
When a page that contains the malicious HTML code is viewed, Internet Explorer and all instances of Internet Explorer that are spawned from the instance used to view the malicious page, will crash.
Microsoft Internet Explorer is reported prone to a remote denial of service vulnerability.
The issue presents itself due to a malfunction that occurs when certain font tags are encountered and rendered.
When a page that contains the malicious HTML code is viewed, Internet Explorer and all instances of Internet Explorer that are spawned from the instance used to view the malicious page, will crash.
Exploit / POC
Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
The following example is available:
<div style="vertical-align:top;">
<p>First <font size="4">Paragraph</p>
<p>Second </font> Paragraph</p>
</div>
The following example is available:
<div style="vertical-align:top;">
<p>First <font size="4">Paragraph</p>
<p>Second </font> Paragraph</p>
</div>
Solution / Fix
Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
References:
References:
- IE vertical-align:top vulnerability (Jehiah Czebotar)
- Technet Security (Microsoft)