OSVDB ID: 27110

Title: Microsoft IE WebViewFolderIcon setSlice Overflow

Info

Disclosure

Jul 17, 2006

Discovery

Unknown

Dates

Exploit

Jul 17, 2006

Solution

Unknown

Description

Internet Explorer contains a flaw that may allow a remote denial of service. The issue is triggered when calling the 'setSlice' method of the WebViewFolderIcon.WebViewFolderIcon.1 ActiveX object with the first parameter set to 0x7fffffff. This causes an invalid memory copy and may result in arbitrary code execution and/or a loss of availability for the browser.

Classification

Location: Remote/Network Access Required
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Integrity, Loss of Availability
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Microsoft Corporation

Internet Explorer

6

References

Credit

  • H D Moore - hdmBrand New Doo Doometasploit.com - DigitalOffense


Direct URL: http://osvdb.org/36218