Vulnerability Development mailing list archives

Re: IE 5.x (5.50.4522.1800 SP1) Crash at gopher://:


From: "Don Tansey" <hyghlander () mindspring com>
Date: Wed, 16 May 2001 22:15:20 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I tried to replicate this in IE Explorer 5.00.2614.3500 and could
not.


1. type shell://: hit return. Normal extra window appear
 2. type shell://:; hit return. TWO extra windows appear
 3. type shell://:;; hit return. 2 or 3 extra windows appear
 4. type shell://: hit return. Explorer comes back with an exception
error:

**In every case I received a Page Cannot Be Displayed error and a
reference to:   
res://C:\Windows\System\shdoclc.dll\syntax.htm#shell://

Attempting the original gopher://: caused Explorer to crash 
with the folowing details:
 
IEXPLORE caused an invalid page fault in
module WININET.DLL at 0167:762bea7c.
Registers:
EAX=00000000 CS=0167 EIP=762bea7c EFLGS=00010246
EBX=00000000 SS=016f ESP=0116fbd8 EBP=0116fe9c
ECX=00000000 DS=016f ESI=00441bb0 FS=6187
EDX=0116fba0 ES=016f EDI=00000000 GS=0000
Bytes at CS:EIP:
88 1c 08 8b 4d 0c 38 19 0f 84 44 01 00 00 66 ba 
Stack dump:
00520b58 00441bb0 00000008 0116fc18 00000034 0116fc18 00000034
0116fc14 00000000 0116fd18 0116fc4c 7b4134a1 000000c0 762df4f8
762e07d0 00000000 


- --Beware the fury of a patient man.

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBOwM0N377bb9Ex5zDEQKGIgCdGhULHKZIVAQeESpqbMwjEsYW+yAAoKdH
9xqNtIl+4byu1W/57LHvqKwO
=xmpL
-----END PGP SIGNATURE-----



Current thread: