PT-2006-1608 · Microsoft · Internet Explorer
Publicado
2006-02-04
·
Atualizado
2008-09-05
·
CVE-2006-0544
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer version 7.0 beta 2 (aka 7.0.5296.0)
Description
The issue allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code. This is achieved by using a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash or hyphen) characters.
Recommendations
For Internet Explorer version 7.0 beta 2, consider avoiding the use of BGSOUND elements with SRC attributes that could trigger this issue until a fix is available. As a temporary workaround, restrict the handling of "file://" URLs in the application to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer