Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
BID:19530
CVE-2006-4193 |Info
Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
| Bugtraq ID: | 19530 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2006 12:00AM |
| Updated: | Aug 16 2006 03:25PM |
| Credit: | nop has been credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.
This issue occurs because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users, and may cause arbitrary code to run within the context of the application.
Microsoft Internet Explorer is prone to a denial-of-service vulnerability.
This issue occurs because the application fails to load a DLL library when instantiated as an ActiveX control.
An attacker may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users, and may cause arbitrary code to run within the context of the application.
Exploit / POC
Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
Attackers can exploit this issue via a web client.
The following proof of concept is available:
Attackers can exploit this issue via a web client.
The following proof of concept is available:
Solution / Fix
Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
References:
References: