Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
BID:19228
Info
Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
| Bugtraq ID: | 19228 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-7066 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | This issue has been discovered by hdm. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
Microsoft Internet Explorer is prone to a denial-of-service vulnerability. This issue is triggered when an attacker convinces a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.
Microsoft Internet Explorer is prone to a denial-of-service vulnerability. This issue is triggered when an attacker convinces a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.
Exploit / POC
Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
A specific exploit is not required.
An example proof of concept has been provided:
A specific exploit is not required.
An example proof of concept has been provided:
Solution / Fix
Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
Solution:
The researcher responsible for discovering this issue has reported that Microsoft has silently addressed this issue in Microsoft Security Bulletin MS06-042. Symantec was not able to confirm this information. Please see the references for more information.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
Solution:
The researcher responsible for discovering this issue has reported that Microsoft has silently addressed this issue in Microsoft Security Bulletin MS06-042. Symantec was not able to confirm this information. Please see the references for more information.
Microsoft Security Bulletin MS06-042 has been updated to address a flaw in Mshtml.dll that was introduced in the previous fixes. Please see the referenced advisory for more information.
References
Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
References:
References:
- Internet Explorer Homepage (Microsoft)
- KB926840: Internet Explorer 6 may close unexpectedly, and an access violation ma (Microsoft)
- MoBB #30: Orphan Object Properties (hdm)
- MS06-042 - Cumulative Security Update for Internet Explorer (918899) (Microsoft)
- MS06-042: One Silent Fix, One No Fix (Aviv Raff)