Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
BID:19640
CVE-2006-4301 |Info
Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
| Bugtraq ID: | 19640 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2006 12:00AM |
| Updated: | Aug 30 2006 05:08PM |
| Credit: | XSec is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
Microsoft Internet Explorer is prone to multiple denial-of-service vulnerabilities that occur when instantiating COM objects.
The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, but this has not been confirmed.
This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). However, these issues affect a different set of COM objects that were not addressed in the previous BIDs.
Microsoft Internet Explorer is prone to multiple denial-of-service vulnerabilities that occur when instantiating COM objects.
The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls, resulting in denial-of-service conditions. Remote code execution may be possible, but this has not been confirmed.
This BID may be related to the issues described in BID 14511 (Microsoft Internet Explorer COM Object Instantiation Buffer Overflow Vulnerability) and BID 15061 Microsoft Internet Explorer COM Object Instantiation Variant Vulnerability). However, these issues affect a different set of COM objects that were not addressed in the previous BIDs.
Exploit / POC
Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
The following HTML code is available to demonstrate these issues:
The following HTML code is available to demonstrate these issues:
Solution / Fix
Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
References:
References: