Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
BID:7502
Info
Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
| Bugtraq ID: | 7502 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2003 12:00AM |
| Updated: | May 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "David F. Madrid" <[email protected]>. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
Microsoft Internet Explorer has been reported prone to a denial of service condition when handling certain DHTML objects.
It has been reported that an attacker may craft a malicious DHTML page containing a malformed 'AnchorClick' link, upon following the malicious link, Internet Explorer will fail. This issue is believed to be as a result of an illegal exception thrown while attempting to access a null pointer.
This issue will only affect the active Internet Explorer window, inactive Internet Explorer windows are not affected.
It should be noted that, although this vulnerability has been reported to affect Internet Explorer version 6.0 SP1, previous versions might also be affected.
Microsoft Internet Explorer has been reported prone to a denial of service condition when handling certain DHTML objects.
It has been reported that an attacker may craft a malicious DHTML page containing a malformed 'AnchorClick' link, upon following the malicious link, Internet Explorer will fail. This issue is believed to be as a result of an illegal exception thrown while attempting to access a null pointer.
This issue will only affect the active Internet Explorer window, inactive Internet Explorer windows are not affected.
It should be noted that, although this vulnerability has been reported to affect Internet Explorer version 6.0 SP1, previous versions might also be affected.
Exploit / POC
Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
References:
References:
- Crash in Internet Explorer 6.0 Sp1 ("David F. Madrid"
)