SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Web Browser)  >  Microsoft Internet Explorer (IE) Vendors:  Microsoft
Microsoft Internet Explorer Can Be Crashed By Remote Users With Large Text Files
SecurityTracker Alert ID:  1010673
SecurityTracker URL:  http://securitytracker.com/id?1010673
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Jul 12 2004
Impact:  Denial of service via network
Exploit Included:  Yes  
Version(s): Tested on 6.0.2800.1106.xpsp2.030422-1633
Description:  Paul Kurczaba reported a denial of service vulnerability in Microsoft Internet Explorer (IE). A remote user can create HTML that, when loaded by the target user, will cause the target user's browser to

It is reported that a remote user can create a large text file of approximately 4 MB that, when loaded by the target user, will cause IE to hang. A manual termination of the process is required, the report said.

A demonstration exploit is available at:

http://www.kurczaba.com/securityadvisories/0 407111poc.txt

The original advisory is available at:

http://www.kurczaba.com/securityadvisories/0407111.htm

Impact:  A remote user can create a text file that will cause the target users IE browser to hang indefinitely.
Solution:  No solution was available at the time of this entry.
Vendor URL:  www.microsoft.com/technet/security/ (Links to External Site)
Cause:  State error
Underlying OS:  Windows (Any)
Reported By:  Kurczaba Associates advisories <advisories@kurczaba.com>
Message History:   None.


 Source Message Contents

Date:  Sun, 11 Jul 2004 23:24:32 -0400
From:  Kurczaba Associates advisories <advisories@kurczaba.com>
Subject:  Internet Explorer Large Text File Denial of Service

 
 
Internet Explorer Large Text File Denial of Service
 
http://www.kurczaba.com/securityadvisories/0407111.htm
-------------------------------------------------------------
 
Vulnerability ID Number:
0407111
 
 
Overview:
A Denial of Service (DoS) vulnerability has been found in Microsoft Internet Explorer.
 
 
Vendor:
Microsoft (http://www.microsoft.com)
 
 
Affected Systems/Configuration:
This test was done on a Windows XP Professional machine, with the latest version of Internet Explorer
(6.0.2800.1106.xpsp2.030422-1633). All Microsoft security patches (hotfixes) and service packs are i
nstalled Vulnerability/Exploit: It is possible to crash Internet Explorer by browsing a specially crafted, large text file. The one I
used to test was 4 megabytes and contained all \\\"1\\\"s. After about ten seconds, Intern
et Explorer will stop responding. Workaround: None. Program must be terminated by Task Manager Date Discovered: July 6, 2004 Severity: Medium Credit: Paul Kurczaba Kurczaba Associates http://www.kurczaba.com/ Discussion of this vulnerability can be found at: http://forums.kurczaba.com/forum_topics.asp?FID=12 Visit http://www.kurczaba.com/mailinglists.htm for mailing lists in Security, Encryption, Wireless, M
S-Security, and Production Security.


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC