Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
BID:33494
Info
Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
| Bugtraq ID: | 33494 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-0341 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2009 12:00AM |
| Updated: | Feb 11 2009 07:28PM |
| Credit: | Juan Pablo Lopez Yacubian |
| Vulnerable: |
Microsoft Internet Explorer 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue may allow an attacker to crash the browser, which will result in a denial-of-service condition.
Internet Explorer 7 on Windows XP SP3 is vulnerable; other versions running on different platforms may also be affected.
NOTE: This issue was originally published as a buffer-overflow vulnerability that could result in remote code execution. Further analysis and vendor reports, however, suggest that exploiting this issue may cause only a denial-of-service condition from stack exhaustion. This vulnerability cannot be exploited to execute arbitrary code.
Microsoft Internet Explorer is prone to a denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue may allow an attacker to crash the browser, which will result in a denial-of-service condition.
Internet Explorer 7 on Windows XP SP3 is vulnerable; other versions running on different platforms may also be affected.
NOTE: This issue was originally published as a buffer-overflow vulnerability that could result in remote code execution. Further analysis and vendor reports, however, suggest that exploiting this issue may cause only a denial-of-service condition from stack exhaustion. This vulnerability cannot be exploited to execute arbitrary code.
Exploit / POC
Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to interact with a malicious webpage.
The following exploit is available:
An attacker can exploit this issue by enticing an unsuspecting victim to interact with a malicious webpage.
The following exploit is available:
Solution / Fix
Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
References:
References: