Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
BID:15208
Info
Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
| Bugtraq ID: | 15208 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2005 12:00AM |
| Updated: | Oct 26 2005 12:00AM |
| Credit: | Tom Ferris is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
Microsoft Internet Explorer is affected by a denial of service vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner. This issue only presents itself when the J2SE Java runtime environment is installed.
An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application.
Microsoft Internet Explorer 6 SP2 is affected by this issue.
Microsoft Internet Explorer is affected by a denial of service vulnerability. This issue arises because the application fails to handle exceptional conditions in a proper manner. This issue only presents itself when the J2SE Java runtime environment is installed.
An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application.
Microsoft Internet Explorer 6 SP2 is affected by this issue.
Exploit / POC
Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
An exploit is not required.
The following proof of concept is available:
<FRAMESET >
<FRAME SRC=AAAA >
<EMBED NAME=SP STYLE= >
<APPLET HSPACE=file://AAAA >
An exploit is not required.
The following proof of concept is available:
<FRAMESET >
<FRAME SRC=AAAA >
<EMBED NAME=SP STYLE= >
<APPLET HSPACE=file://AAAA >
Solution / Fix
Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
References:
References:
- Internet Explorer 'mshtmled.dll' 6.0 Denial Of Service (Security-Protocols.com)
- Mozilla Firefox Home Page (Mozilla)