Nokia Browser HTML Denial of Service Vulnerability
BID:19484
CVE-2006-4464 |Info
Nokia Browser HTML Denial of Service Vulnerability
| Bugtraq ID: | 19484 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2006 12:00AM |
| Updated: | Aug 11 2006 11:25PM |
| Credit: | Qode is credited with the discovery of this issue. |
| Vulnerable: |
Nokia Browser 0 |
| Not Vulnerable: | |
Discussion
Nokia Browser HTML Denial of Service Vulnerability
Nokia Browser is prone to a denial-of-service vulnerability when handling malicious HTML files.
A successful exploit of this issue allows attackers to consume excessive system resources in the affected browser, resulting in the application crashing, denying service to legitimate users. Remote code execution may be possible, but this has not been confirmed.
Nokia Browser is prone to a denial-of-service vulnerability when handling malicious HTML files.
A successful exploit of this issue allows attackers to consume excessive system resources in the affected browser, resulting in the application crashing, denying service to legitimate users. Remote code execution may be possible, but this has not been confirmed.
Exploit / POC
Nokia Browser HTML Denial of Service Vulnerability
The following HTML code is sufficient to trigger this issue:
The following HTML code is sufficient to trigger this issue:
Solution / Fix
Nokia Browser HTML Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Nokia Browser HTML Denial of Service Vulnerability
References:
References:
- Nokia Homepage (Nokia)
- Nokia Browser Crash (Qode)