The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  IE and OE crash over malformed XBM image
Time: 15:41 EST/20:41 GMT | News Source: Neowin | Posted By: Alex Harris

Read this over on Neowin:

Internet Explorer allows the usage of XBM graphic files and tries to display them whenever they are used in any HTML file [as IMG tag] or when attached to an e-mail. A vulnerability has been found in the way Internet Explorer handles malformed XBM files, where it is possible for a malicious user to cause the IE to crash whilst consuming a large amount of CPU and memory (which is not freed upon the completion of the crash).

Vulnerable systems: Internet Explorer 5.5, 6.0, Outlook Express 5.0, 6.0 The vunerability exists because IE does not check the width and height of the image defined in a XBM file, so you may write whatever you want and IE will try to interpret it. IE will take these width and heigh dimensions and try to allocate enough memory for an oversized buffer which results in forcing the browser/e-mail client to hang up, ending up in their silent exit because of the Access Violation exception inside mshtml.dll.

When previewed for example in Outlook Express, malformed e-mail may force this client to exit (and others that rely on IE).

View: Demonstration of malformed e-mail

Write Comment
Return to News

  Displaying 301 through 304 of 304
Prev | First
  The time now is 4:02:54 AM ET.
Any comment problems? E-mail us
#301 By 4240821 (212.193.138.162) at 11/26/2024 5:32:50 AM
https://justpaste.me/CHW22
https://justpaste.me/CDfg3
https://justpaste.me/Bfy64
https://justpaste.me/Bw20
https://justpaste.me/BmHx2
https://justpaste.me/CQXv2
https://justpaste.me/CLKI
https://justpaste.me/CaPQ4
https://justpaste.me/C5fl
https://justpaste.me/CED11

#302 By 4240821 (82.117.86.164) at 11/26/2024 4:50:55 PM
https://justpaste.me/BcSI1
https://justpaste.me/CVYv1
https://justpaste.me/CRlY2
https://justpaste.me/CPHY1
https://justpaste.me/BvpM1
https://justpaste.me/C6Dh
https://justpaste.me/Bb6H2
https://justpaste.me/CfHJ4
https://justpaste.me/BeNo1
https://justpaste.me/C22g

#303 By 4240821 (77.83.4.69) at 11/26/2024 8:13:08 PM
https://www.google.pn/amp/s/sluts.su/get/a168/a168wvfcqzaxzqzvccw.php
https://www.google.ro/amp/s/sluts.su/get/a110/a110xwrnzgavdngxifw.php
https://www.google.pn/amp/s/sexonly.top/get/a58/a58atwvinsalcfweyc.php
https://www.google.pn/amp/s/sluts.su/get/a210/a210loxgpcxcbeniyyy.php
https://www.google.rs/amp/s/lustful.su/get/a115/a115emwpgzjrknlkyrb.php
https://www.google.pt/amp/s/sluts.su/get/a185/a185mrrehhsryqskrrn.php
https://www.google.pn/amp/s/sluts.su/get/a119/a119bybvzljkyqguflq.php
https://www.google.sc/amp/s/sluts.su/get/a291/a291bdoksqlvexhfolz.php
https://www.google.ps/amp/s/sluts.su/get/a259/a259byvklkuvwnnbmqa.php
https://www.google.pn/amp/s/sluts.su/get/a5/a5hettnkcwlaxlwkw.php

#304 By 4240821 (77.83.4.69) at 11/28/2024 3:54:35 AM
https://telegra.ph/IvanaKnoll-knolldoll-Hidden-Cam-Patreon-Leaked-11-30
https://telegra.ph/LanaRhoades-Nun-Boosty-Leak-12-21
https://168.exodirectory.com/index.php?topic=77728.new
https://telegra.ph/Ffaallen-Nurse-Boosty-Leak-01-13
https://git.guildofwriters.org/montrolegli406
http://activewin.com/mac/comments.asp?ThreadIndex=59847
https://telegra.ph/AngelaWhite-Watching-Fansly-Leak-12-20
https://telegra.ph/AngelaWhite-Exhibitionist-Clips4sale-Leak-12-18
https://git.guildofwriters.org/procuturtin963
http://activewin.com/mac/comments.asp?ThreadIndex=14312

Write Comment
Return to News
  Displaying 301 through 304 of 304
Prev | First
  The time now is 4:02:54 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *