Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
BID:7384
Info
Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
| Bugtraq ID: | 7384 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2003 12:00AM |
| Updated: | Apr 18 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Adam Blaszczyk <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
Microsoft Internet Explorer contains a vulnerability that may allow for malicious webmasters to cause a victim user's web browser to stop responding.
If a web page contains a specific CLASSID value and an IE user attempts to view the page, IE has been reported to crash. The reported offending CLASSID is CLSID:0CF32AA1-7571-11D0-93C4-00AA00A3DDEA, however, there may be other CLASSID values which could exploit this issue.
Microsoft Internet Explorer contains a vulnerability that may allow for malicious webmasters to cause a victim user's web browser to stop responding.
If a web page contains a specific CLASSID value and an IE user attempts to view the page, IE has been reported to crash. The reported offending CLASSID is CLSID:0CF32AA1-7571-11D0-93C4-00AA00A3DDEA, however, there may be other CLASSID values which could exploit this issue.
Exploit / POC
Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
References:
References:
- Technet Security (Microsoft)
- IE 6.0 - trivial crash - part II ("Adam \[ckkl\]"
)