Microsoft Internet Explorer/Outlook Express XBM Handling DoS Vulnerability
BID:4653
Info
Microsoft Internet Explorer/Outlook Express XBM Handling DoS Vulnerability
| Bugtraq ID: | 4653 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2002 12:00AM |
| Updated: | May 01 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Adam [wp-ckkl]" <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer/Outlook Express XBM Handling DoS Vulnerability
Microsoft Internet Explorer and Outlook Express crash when handling malformed XBM image files in webpages, HTML e-mail, or as an e-mail attachment. This is believed to be the result of insufficient checking of the content in XBM files. MSIE allocates memory to store the image based (partly) on the width and height specified. It may be possible for attackers to specify excessive values, resulting in exhaustion of system memory or access violation errors.
Other software which relies upon Internet Explorer may also crash when handling malformed XBM files.
Microsoft Internet Explorer and Outlook Express crash when handling malformed XBM image files in webpages, HTML e-mail, or as an e-mail attachment. This is believed to be the result of insufficient checking of the content in XBM files. MSIE allocates memory to store the image based (partly) on the width and height specified. It may be possible for attackers to specify excessive values, resulting in exhaustion of system memory or access violation errors.
Other software which relies upon Internet Explorer may also crash when handling malformed XBM files.
Exploit / POC
Microsoft Internet Explorer/Outlook Express XBM Handling DoS Vulnerability
A proof-of-concept is included on the following webpage:
http://www.sztolnia.pl/hack/xbmbug/xbmbug.eml
A proof-of-concept is included on the following webpage:
http://www.sztolnia.pl/hack/xbmbug/xbmbug.eml
Solution / Fix
Microsoft Internet Explorer/Outlook Express XBM Handling DoS Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.