Multiple Browser Marquee Denial of Service Vulnerability
BID:18165
CVE-2006-2723 |Info
Multiple Browser Marquee Denial of Service Vulnerability
| Bugtraq ID: | 18165 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-2723 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2006 12:00AM |
| Updated: | Feb 04 2010 08:51PM |
| Credit: | n00b is credited with the discovery of this issue. |
| Vulnerable: |
Opera Software Opera Web Browser 8.51 Opera Software Opera Web Browser 8.50 Opera Software Opera Web Browser 8.0 2 Opera Software Opera Web Browser 8.0 1 Opera Software Opera Web Browser 8.0 Opera Software Opera Web Browser 8.54 Opera Software Opera Web Browser 8.53 Opera Software Opera Web Browser 8.52 Opera Software Opera Web Browser 8 Beta 3 Nokia N95 Phone 0 Mozilla SeaMonkey 1.1.14 Mozilla SeaMonkey 1.1.13 Mozilla SeaMonkey 1.1.12 Mozilla SeaMonkey 1.1.11 Mozilla Grand Paradiso 3.0a1 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .17 Mozilla Firefox 2.0 .16 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 3.0 Beta 5 Mozilla Firefox 3.0 Mozilla Firefox 2.0.0.3 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.18 Mozilla Firefox 2.0.0.15 Mozilla Firefox 2.0.0.14 Mozilla Firefox 2.0.0.13 Mozilla Firefox 2.0.0.12 Mozilla Firefox 2.0.0.11 Mozilla Firefox 2.0.0.10 Mozilla Firefox 2.0.0.10 Mozilla Firefox 1.5.0.3 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Flock Flock 0.7 Apple Safari 4.0.4 for Windows Apple Safari 4.0.4 Apple Safari 4.0.3 for Windows Apple Safari 4.0.3 Apple Safari 4.0.2 for Windows Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 4 for Windows Apple Safari 4 Beta |
| Not Vulnerable: | |
Discussion
Multiple Browser Marquee Denial of Service Vulnerability
Multiple browsers are prone to a denial-of-service vulnerability when parsing certain HTML content.
Successfully exploiting this issue allows attackers to consume excessive CPU resources in affected browsers, denying service to legitimate users.
The following are vulnerable:
Mozilla Firefox 1.5.0.3
Internet Explorer 6.0 on Microsoft Windows XP
Other versions and products may also be affected.
Multiple browsers are prone to a denial-of-service vulnerability when parsing certain HTML content.
Successfully exploiting this issue allows attackers to consume excessive CPU resources in affected browsers, denying service to legitimate users.
The following are vulnerable:
Mozilla Firefox 1.5.0.3
Internet Explorer 6.0 on Microsoft Windows XP
Other versions and products may also be affected.
Exploit / POC
Multiple Browser Marquee Denial of Service Vulnerability
The following example exploits are available:
The following example exploits are available:
- /data/vulnerabilities/exploits/18165-safari.html
- /data/vulnerabilities/exploits/18165.html
- /data/vulnerabilities/exploits/Marque-0607-exp.html
- /data/vulnerabilities/exploits/Marque-0608-opera.html
- /data/vulnerabilities/exploits/18165.py
- /data/vulnerabilities/exploits/18165-liquidworm.html
- /data/vulnerabilities/exploits/18165-athos.pl
Solution / Fix
Multiple Browser Marquee Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Browser Marquee Denial of Service Vulnerability
References:
References:
- Bugzilla Bug 339954 - using many nested marquee crashes firefox 1.5.0 (Bugzilla)
- SeaMonkey Homepage (Mozilla)
- Fire fox dos exploit ([email protected])
- flock d0s exploit remote. beta 1 (v0.7) ( [email protected])
- Ie opera dos exploit ([email protected])
- Nokia N95-8 browser denial of service ([email protected])
- Re: [Bugtraq] Re: flock d0s exploit remote. beta 1 (v0.7) ([email protected])
- Re: Fire fox dos exploit (Yannick von Arx
) - Re: Fire fox dos exploit (Phil Trainor
) - RE: Fire fox dos exploit (Jaroslaw Sajko
)