evolve or die

memcorruptIE.txt

memcorruptIE.txt
Posted Jul 3, 2004
Authored by Phuong Nguyen

An 11 byte attack against Microsoft Internet Explorer allows for an attacker to denial of service the application due to a memory corruption vulnerability. Versions affected: 5.x, 6.1 SP1.

tags | advisory, denial of service
MD5 | cb16ac1e7998cbf382f0139889778d75

memcorruptIE.txt

Change Mirror Download
TITLE
=====
Memory Corruption Vulnerability

DESCRIPTION
===========
Internet Explorer is the flagship broswer for the Microsoft Windows OS.

PROBLEM
=======
Affected Versions : Internet Explorer 5.x, 6.1 SP1
Tested Platforms : Windows 2k, Windows XP

Internet Explorer is vulnerable to numerous security holes, and this
one is not that big of a deal, but worth
mentioning. This memory corruption vulnerability allows an attacker to
DoS the application itself, no more no less.
An attacker can shutdown Internet Explorer with only 11 bytes.

DETAILS
=======
[Cascading Style Sheet(CSS) Memory Corruption]

There are 1001 ways that an attacker can use to hack, exploit, and
crash IE but we believe this is one of the most
compact attacks ever, as an attacker needs only 11 bytes to crash IE.
This vulnerability does not give the attacker the
ability to exploit and execute arbitrary code or cause any real damage
to the victim, but rather it corrupts the memory space
allocated by IE.

There was a similar vulnerability which has been reported earlier, but
this one is more compact.
IE seems to have problems handling Cascading Style Sheet (CSS) elements
and therefore an attacker can easily crash IE by using
the following, imho, weird combinations of CSS elements:

<STYLE>@;/*

There you go, 11 bytes is all it takes to crash IE. Having <STYLE>@;/*
alone is enough, other <HTML> tags are not necessary.
If you're too lazy to test this yourself, then we have conveniently
created a sample 11 byte html at:

http://www.ecqurity.com/adv/11.html

VENDOR STATUS
=============
This would most likely be small problem to Microsoft and we decided not
to report it. Internet Explorer still has quite a few
serious unpatched security holes in it, and we don't think this one
deserves Microsoft's attention. In the meantime, perhaps
using a different browser to surf the web is in order.

CONTACT
=======

phuong at ecqurity .com
david at ecqurity .com
http://www.ecqurity.com




__________________________________
Do you Yahoo!?
New and Improved Yahoo! Mail - Send 10MB messages!
http://promotions.yahoo.com/new_mail

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close