Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.900131
Kategorie:Denial of Service
Titel:Microsoft Internet Explorer Denial of Service Vulnerability
Zusammenfassung:The host has Microsoft Internet Explorer installed, which is prone; to denial of service vulnerability.
Beschreibung:Summary:
The host has Microsoft Internet Explorer installed, which is prone
to denial of service vulnerability.

Vulnerability Insight:
Due to errors while handling PNG files, CDwnTaskExec::ThreadExec enters
into an infinite loop while loading images which causes the browser to crash. This can be exploited by
enticing victim to visit a malicious web page embedded with rogue PNG files.

Vulnerability Impact:
Successful exploitation will cause the application to stop
responding and denying the service to legitimate users.

Affected Software/OS:
Microsoft Internet Explorer 7.x and 8 Beta.

Solution:
No known solution was made available for at least one year since the disclosure
of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer
release, disable respective features, remove the product or replace the product by another one.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Querverweis: BugTraq ID: 31215
Common Vulnerability Exposure (CVE) ID: CVE-2008-4127
http://www.securityfocus.com/bid/31215
Bugtraq: 20080917 Microsoft Internet Explorer DoS in Rendering Malicious PNG Files. (Google Search)
http://www.securityfocus.com/archive/1/496483/100/0/threaded
http://securityreason.com/securityalert/4273
XForce ISS Database: ie-png-dos(45225)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45225
CopyrightCopyright (C) 2008 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.