|
Microsoft Internet Explorer 5 Favicon Buffer Overflow Vulnerability
A vulnerability in Internet Explorer 5's processing of the icon used in the "Favorites" menu may allow malicious web sites to execute arbitrary code in the users machine. A new feature of Internet Explorer 5.0 allows web site operators to custumize the display of their bookmark entry with an icon when it is displayed in the "Favorites" menu. When the user bookmarks a page IE will request the file "favicon.ico" from the web site. This feature is only available in Win32 platforms using a Win32 icon format. A malformed icon can cause a stack buffer oveflow in IE 5.0. The GPF is triggered in the USER.EXE module. |
|
Privacy Statement |