Stack Overflow Denial Of Service in Outlook, Internet Explorer and Outlook Express
A DLL used to parse HTML has be found to be vulnerable to a buffer overflow.
January 14, 2001
Reported January 15, 2001, by Win2KSecAdvice VERSIONS AFFECTED DESCRIPTIONA low-risk stack overflow has been discovered in the .dll file responsible for parsing HTML. Any program such as Internet Explorer (IE), Outlook, and Outlook Express that uses mshtml.dll is vulnerable. This vulnerability is low risk because the overflow does not let intruders launch arbitrary commands but simply crash the affected program. DEMONSTRATION The following code was provided by Thor Larholm: ------------InstantCrash.html----------------- ---------------------------------------------- VENDOR RESPONSE Microsoft was notified on December 4, 2000. According to Thor Larholm, Microsoft will address this bug in the next service pack for IE. CREDITDiscovered by Thor Larholm. |
About the Author
You May Also Like