Microsoft Internet Explorer HTML Denial of Service Vulnerability
BID:23178
Info
Microsoft Internet Explorer HTML Denial of Service Vulnerability
| Bugtraq ID: | 23178 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2007 12:00AM |
| Updated: | Mar 28 2007 07:53PM |
| Credit: | Shinnai is credited with discovering this vulnerability. |
| Vulnerable: |
Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTML Denial of Service Vulnerability
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions.
This issue is triggered when an attacker entices a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.
This issue affects Internet Explorer version 7.
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because the application fails to handle exceptional conditions.
This issue is triggered when an attacker entices a victim user to visit a malicious website.
Remote attackers may exploit this issue to crash Internet Explorer, effectively denying service to legitimate users.
This issue affects Internet Explorer version 7.
Exploit / POC
Microsoft Internet Explorer HTML Denial of Service Vulnerability
An attacker may exploit this issue by enticing victims into viewing malicious HTML content.
The following exploit is available:
An attacker may exploit this issue by enticing victims into viewing malicious HTML content.
The following exploit is available:
Solution / Fix
Microsoft Internet Explorer HTML Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft Internet Explorer HTML Denial of Service Vulnerability
References:
References:
- Internet Explorer Homepage (Microsoft)