Re: IE6 SP1 - Trivial Crash

From: MARLON BORBA (MBORBAat_private)
Date: Tue Jul 29 2003 - 12:54:22 PDT

  • Next message: Mike Kristovich: "[Full-Disclosure] GameSpy Arcade Arbitrary File Writing Vulnerability"

    confirmed here. windows 2000 and ie with their latest service packs.
    as a side note, tested with mozilla. at first nothing strange seen (it
    even displays a message saying '1.html - file not found'), but when i
    select 'view/page source', it quickly crashes.
    
    bye,
    
    marlon.
    
    >>> "James Wolfe" <jamesat_private> 07/29 11:06 am >>>
    Overview/Description:
    
        In March of 2000, someone posted to bugtraq a flaw in the MS
    Outlook
    Express ActiveX control which allowed for "the reading of any file on
    the
    users machine." My guess is that MS, in an attempt to bugfix it, didnt
    debug
    properly and left the following new bug.
    



    This archive was generated by hypermail 2b30 : Wed Jul 30 2003 - 11:38:40 PDT