Bugtraq mailing list archives
Re: Update: Web browsers - a mini-farce (MSIE gives in)
From: MCMuir () dstoutput com
Date: Wed, 27 Oct 2004 11:09:55 -0700
6.0.2800.1106 on Win 2k Pro (5.00.2195 SP4) does not crash. -mike <gabrield89 () hotmail com> wrote on 10/25/2004 08:00:44 AM:
In-Reply-To: <20041023001154.F23256 () dekadens coredump cx>Last but not least, MSIE gives in:Only MSIE appears to be able to consistently handle [*] malformedinput well, suggesting this is the only program that underwentrudimentary security QA testing with a similar fuzz utility.To all those who considered my original post to be a great propagandaammunition for praising MSIE, bad news - although it did take a longerwhile for it to give up - three hours - (impressive by comparison tocompetitors), it eventually did:http://lcamtuf.coredump.cx/mangleme/gallery/ie_die1.htmlTested on 6.0.2800.1106, dies in mshtml.dll. This is a NULL pointerdereference, so merely a DoS condition, but still an evident flaw inbasic HTML parsing.Testing on Windows 98 running IE 6.0.2800.1106. Nothing happens. IE does not crash. Can anyone else confirm this?
Current thread:
- RE: Update: Web browsers - a mini-farce (MSIE gives in) David Brodbeck (Oct 25)
- Re: Update: Web browsers - a mini-farce (MSIE gives in) Valdis . Kletnieks (Oct 27)
- <Possible follow-ups>
- Re: Update: Web browsers - a mini-farce (MSIE gives in) gabrield89 (Oct 25)
- Re: Update: Web browsers - a mini-farce (MSIE gives in) MCMuir (Oct 28)
- RE: Update: Web browsers - a mini-farce (MSIE gives in) Michael Wojcik (Oct 27)
- Re: Update: Web browsers - a mini-farce (MSIE gives in) Valdis . Kletnieks (Oct 27)
- Re: Update: Web browsers - a mini-farce (MSIE gives in) Chris Paget (Oct 29)
- RE: Update: Web browsers - a mini-farce (MSIE gives in) Michael Wojcik (Oct 27)
- Re: Update: Web browsers - a mini-farce (MSIE gives in) Valdis . Kletnieks (Oct 28)
- RE: Update: Web browsers - a mini-farce (MSIE gives in) David Brodbeck (Oct 28)
- RE: Update: Web browsers - a mini-farce (MSIE gives in) Michael Wojcik (Oct 28)
- RE: Update: Web browsers - a mini-farce (MSIE gives in) Tim Newsham (Oct 29)
- Re: Update: Web browsers - a mini-farce (MSIE gives in) Michael Shigorin (Oct 29)
- RE: Update: Web browsers - a mini-farce (MSIE gives in) David Brodbeck (Oct 29)
(Thread continues...)