Microsoft IE for Solaris X Server Denial of Service Vulnerability
BID:3729
Info
Microsoft IE for Solaris X Server Denial of Service Vulnerability
| Bugtraq ID: | 3729 |
| Class: | Design Error |
| CVE: |
CVE-2001-1218 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 20 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by Jing Shen <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer for Unix 5.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft IE for Solaris X Server Denial of Service Vulnerability
It has been reported that in some situations, Internet Explorer 5.0 SP1 for Solaris is able to crash the X server. In particular, this has been reported with Chinese versions of the software.
If a chinese language web page is displayed, and rapidly scrolled, it is possible to end the user session. The user is ejected back to the initial login prompt. This may also happen if the IE window is maximized. If this is done several times, the X server may crash entirely.
This vulnerability can result in the denial of service to all X users.
It has been reported that in some situations, Internet Explorer 5.0 SP1 for Solaris is able to crash the X server. In particular, this has been reported with Chinese versions of the software.
If a chinese language web page is displayed, and rapidly scrolled, it is possible to end the user session. The user is ejected back to the initial login prompt. This may also happen if the IE window is maximized. If this is done several times, the X server may crash entirely.
This vulnerability can result in the denial of service to all X users.
Exploit / POC
Microsoft IE for Solaris X Server Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IE for Solaris X Server Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IE for Solaris X Server Denial of Service Vulnerability
References:
References: