Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
BID:19013
CVE-2006-3659 |Info
Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
| Bugtraq ID: | 19013 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Jul 18 2006 08:23PM |
| Credit: | H D Moore is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
Internet Explorer is prone to a denial-of-service vulnerability.
The problem occurs when the application is used to view a malicious URI or webpage consisting of a malformed MHTMLfile element.
An attacker can exploit this issue to crash Internet Explorer and deny service to the user.
Internet Explorer 6 SP2 is vulnerable to this issue; other versions may also be vulnerable.
Internet Explorer is prone to a denial-of-service vulnerability.
The problem occurs when the application is used to view a malicious URI or webpage consisting of a malformed MHTMLfile element.
An attacker can exploit this issue to crash Internet Explorer and deny service to the user.
Internet Explorer 6 SP2 is vulnerable to this issue; other versions may also be vulnerable.
Exploit / POC
Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
The following proof of concept is available.
The following proof of concept is available.
Solution / Fix
Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
References:
References:
- Microsoft Internet Explorer 6 Home Page (Microsoft)