Microsoft Internet Explorer New ActiveX Object String Concatenation Memory Corruption Vulnerability
BID:30219
Info
Microsoft Internet Explorer New ActiveX Object String Concatenation Memory Corruption Vulnerability
| Bugtraq ID: | 30219 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2008 12:00AM |
| Updated: | Jul 14 2008 11:39PM |
| Credit: | 0x000000 # The Hacker Webzine |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP2 - do not use Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer New ActiveX Object String Concatenation Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Remote attackers can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability.
Remote attackers can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Exploit / POC
Microsoft Internet Explorer New ActiveX Object String Concatenation Memory Corruption Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
The following sample exploit is available:
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
The following sample exploit is available:
Solution / Fix
Microsoft Internet Explorer New ActiveX Object String Concatenation Memory Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer New ActiveX Object String Concatenation Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- More MSIE 6 Mayhem. (0x000000)