Vulnerability Development mailing list archives

RE: IE crash


From: "Scovetta, Michael V" <Michael.Scovetta () ca com>
Date: Wed, 2 Feb 2005 13:14:34 -0500

Fabio,
   It has very little to do with IE. The hs_err_pidXXXX.log files are
dumps that the JVM makes when it crashes when in native code. 

I belive this JVM bug may be:
        http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=4816519

There are reports of this happening on NT and XP, but since the bug was
reported in Feb, 2003, and still "in progess", I guess Sun isn't going
to get around to fixing it. Perhaps upgrading to 1.5 will help.

Regards,

Michael Scovetta
Computer Associates
Senior Application Developer


-----Original Message-----
From: Fabio Ruini [mailto:fabio.ruini () aliceposta it] 
Sent: Tuesday, February 01, 2005 10:19 AM
To: vuln-dev () securityfocus com
Subject: IE crash

Hi at all,

yesterday evening I was working at my pc, running multiple windows of
Internet Explorer at the same time. When I tried to open the 40th IE's
windows (I know, 40 windows simultaneously open is a big number, but I
had
many reasons to do this kind of operation... :-/) I encountered a crash
of
Internet Explorer. Windows didn't ask me to report the problem to
Microsoft.

Few seconds later, I saw a new text file on my desktop, called
hs_err_pid2832.log. I paste here the content of this file. What do you
think
about this kind of problem? Could it be an exploitable bug of IE?

An unexpected exception has been detected in native code outside the VM.
Unexpected Signal : EXCEPTION_ACCESS_VIOLATION (0xc0000005) occurred at
PC=0x698545F Function=Java_sun_awt_windows_WColor_getDefaultColor+0x2E0B
Library=C:\Programmi\Java\j2re1.4.2_05\bin\awt.dll

Current Java thread:
        at sun.awt.windows.WToolkit.eventLoop(Native Method)
        at sun.awt.windows.WToolkit.run(Unknown Source)
        at java.lang.Thread.run(Unknown Source)

Dynamic libraries:
0x00400000 - 0x00419000         C:\Programmi\Internet
Explorer\iexplore.exe
0x7C910000 - 0x7C9C6000         C:\WINDOWS\system32\ntdll.dll
0x7C800000 - 0x7C8FF000         C:\WINDOWS\system32\kernel32.dll
0x77BE0000 - 0x77C38000         C:\WINDOWS\system32\msvcrt.dll
0x77D10000 - 0x77DA0000         C:\WINDOWS\system32\USER32.dll
0x77E40000 - 0x77E86000         C:\WINDOWS\system32\GDI32.dll
0x77E90000 - 0x77F06000         C:\WINDOWS\system32\SHLWAPI.dll
0x77F40000 - 0x77FEB000         C:\WINDOWS\system32\ADVAPI32.dll
0x77DA0000 - 0x77E31000         C:\WINDOWS\system32\RPCRT4.dll
0x77730000 - 0x7789C000         C:\WINDOWS\system32\SHDOCVW.dll
0x77A50000 - 0x77AE5000         C:\WINDOWS\system32\CRYPT32.dll
0x77AF0000 - 0x77B02000         C:\WINDOWS\system32\MSASN1.dll
0x76890000 - 0x76913000         C:\WINDOWS\system32\CRYPTUI.dll
0x76BF0000 - 0x76C1E000         C:\WINDOWS\system32\WINTRUST.dll
0x76C50000 - 0x76C78000         C:\WINDOWS\system32\IMAGEHLP.dll
0x770F0000 - 0x7717C000         C:\WINDOWS\system32\OLEAUT32.dll
0x774B0000 - 0x775EC000         C:\WINDOWS\system32\ole32.dll
0x5BC70000 - 0x5BCC4000         C:\WINDOWS\system32\NETAPI32.dll
0x77180000 - 0x77227000         C:\WINDOWS\system32\WININET.dll
0x76F20000 - 0x76F4D000         C:\WINDOWS\system32\WLDAP32.dll
0x77BD0000 - 0x77BD8000         C:\WINDOWS\system32\VERSION.dll
0x773A0000 - 0x774A2000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df
_6.0
.2600.2180_x-ww_a84f1ff9\comctl32.dll
0x7C9D0000 - 0x7D1EB000         C:\WINDOWS\system32\SHELL32.dll
0x5D4D0000 - 0x5D567000         C:\WINDOWS\system32\comctl32.dll
0x5B180000 - 0x5B1B8000         C:\WINDOWS\system32\uxtheme.dll
0x10000000 - 0x10148000         C:\Programmi\Messenger Plus!
3\MsgPlusH.dll
0x76360000 - 0x763AA000         C:\WINDOWS\system32\comdlg32.dll
0x003D0000 - 0x003D7000
C:\Programmi\Logitech\MouseWare\System\LgWndHk.dll
0x75F30000 - 0x7602C000         C:\WINDOWS\system32\BROWSEUI.dll
0x20000000 - 0x20013000         C:\WINDOWS\system32\browselc.dll
0x77B10000 - 0x77B32000         C:\WINDOWS\system32\appHelp.dll
0x76F90000 - 0x7700F000         C:\WINDOWS\system32\CLBCATQ.DLL
0x77010000 - 0x770E2000         C:\WINDOWS\system32\COMRes.dll
0x77230000 - 0x772CE000         C:\WINDOWS\system32\urlmon.dll
0x77F10000 - 0x77F21000         C:\WINDOWS\system32\Secur32.dll
0x7D1F0000 - 0x7D4A2000         C:\WINDOWS\system32\msi.dll
0x76980000 - 0x76A34000         C:\WINDOWS\system32\USERENV.dll
0x00AF0000 - 0x00B27000         C:\Programmi\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll
0x7C120000 - 0x7C139000         C:\WINDOWS\system32\ATL71.DLL
0x7C3A0000 - 0x7C41B000         C:\WINDOWS\system32\MSVCP71.dll
0x7C340000 - 0x7C396000         C:\WINDOWS\system32\MSVCR71.dll
0x01220000 - 0x012D3000         c:\programmi\google\googletoolbar1.dll
0x778F0000 - 0x779E7000         C:\WINDOWS\system32\SETUPAPI.dll
0x71A50000 - 0x71A5A000         C:\WINDOWS\system32\WSOCK32.dll
0x71A30000 - 0x71A47000         C:\WINDOWS\system32\WS2_32.dll
0x71A20000 - 0x71A28000         C:\WINDOWS\system32\WS2HELP.dll
0x76B00000 - 0x76B2E000         C:\WINDOWS\system32\WINMM.dll
0x59E60000 - 0x59F01000         C:\WINDOWS\system32\DBGHELP.DLL
0x76EA0000 - 0x76EDC000         C:\WINDOWS\system32\RASAPI32.DLL
0x76E50000 - 0x76E62000         C:\WINDOWS\system32\rasman.dll
0x76E70000 - 0x76E9F000         C:\WINDOWS\system32\TAPI32.dll
0x76E40000 - 0x76E4E000         C:\WINDOWS\system32\rtutils.dll
0x77C40000 - 0x77C63000         C:\WINDOWS\system32\msv1_0.dll
0x76D20000 - 0x76D39000         C:\WINDOWS\system32\iphlpapi.dll
0x72240000 - 0x72245000         C:\WINDOWS\system32\sensapi.dll
0x779F0000 - 0x77A45000         C:\WINDOWS\System32\cscui.dll
0x765B0000 - 0x765CD000         C:\WINDOWS\System32\CSCDLL.dll
0x43000000 - 0x43005000         C:\Programmi\Google\Google Desktop
Search\GoogleDesktopNetwork1.dll
0x44000000 - 0x44019000         C:\Programmi\Google\Google Desktop
Search\GoogleDesktopNetwork2.dll
0x719D0000 - 0x71A10000         C:\WINDOWS\system32\mswsock.dll
0x66750000 - 0x667A8000         C:\WINDOWS\system32\hnetcfg.dll
0x71A10000 - 0x71A18000         C:\WINDOWS\System32\wshtcpip.dll
0x017B0000 - 0x017BE000         C:\Programmi\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
0x41000000 - 0x41013000         C:\Programmi\Google\Google Desktop
Search\GoogleDesktopIE.dll
0x60000000 - 0x6000E000         C:\Programmi\Google\Google Desktop
Search\GoogleDesktopAPI2.dll
0x75E40000 - 0x75EF0000         C:\WINDOWS\system32\SXS.DLL
0x01AD0000 - 0x01AE8000         C:\Programmi\Norton
AntiVirus\NavShExt.dll
0x76AE0000 - 0x76AF1000         C:\WINDOWS\system32\ATL.DLL
0x7C080000 - 0x7C0F7000         C:\WINDOWS\system32\MSVCP70.dll
0x7C000000 - 0x7C054000         C:\WINDOWS\system32\MSVCR70.dll
0x01B10000 - 0x01B9C000         C:\WINDOWS\system32\shdoclc.dll
0x01BA0000 - 0x01E75000         C:\WINDOWS\system32\xpsp2res.dll
0x01E80000 - 0x01EC4000         C:\Programmi\GetRight\XX2GR.DLL
0x72F70000 - 0x72F96000         C:\WINDOWS\system32\WINSPOOL.DRV
0x75D50000 - 0x75DE1000         C:\WINDOWS\system32\mlang.dll
0x022F0000 - 0x022F7000         C:\Programmi\Logitech\iTouch\iTchHk.dll
0x02300000 - 0x0230B000         C:\Programmi\File
comuni\Logitech\Scrolling\LgMsgHk.dll
0x76030000 - 0x76095000         C:\WINDOWS\system32\MSVCP60.dll
0x01510000 - 0x01573000         C:\Programmi\Babylon\CAPTLIB.DLL
0x7D4B0000 - 0x7D793000         C:\WINDOWS\System32\mshtml.dll
0x74650000 - 0x74677000         C:\WINDOWS\System32\msls31.dll
0x74680000 - 0x746AA000         C:\WINDOWS\System32\msimtf.dll
0x746B0000 - 0x746FB000         C:\WINDOWS\System32\MSCTF.dll
0x76340000 - 0x7635D000         C:\WINDOWS\system32\IMM32.DLL
0x325C0000 - 0x325D2000         C:\Programmi\Microsoft
Office\OFFICE11\msohev.dll
0x45000000 - 0x4500C000         C:\Programmi\Google\Google Desktop
Search\gzlib.dll
0x032A0000 - 0x032A7000         C:\Programmi\Logitech\iTouch\kbdhook.dll
0x71AA0000 - 0x71AB2000         C:\WINDOWS\system32\MPR.dll
0x75F10000 - 0x75F17000         C:\WINDOWS\System32\drprov.dll
0x71BA0000 - 0x71BAE000         C:\WINDOWS\System32\ntlanman.dll
0x71C60000 - 0x71C77000         C:\WINDOWS\System32\NETUI0.dll
0x71C20000 - 0x71C60000         C:\WINDOWS\System32\NETUI1.dll
0x71C10000 - 0x71C17000         C:\WINDOWS\System32\NETRAP.dll
0x71B80000 - 0x71B93000         C:\WINDOWS\System32\SAMLIB.dll
0x75F20000 - 0x75F29000         C:\WINDOWS\System32\davclnt.dll
0x75920000 - 0x75A18000         C:\WINDOWS\system32\MSGINA.dll
0x76310000 - 0x76320000         C:\WINDOWS\system32\WINSTA.dll
0x745E0000 - 0x7461D000         C:\WINDOWS\system32\ODBC32.dll
0x033F0000 - 0x03408000         C:\WINDOWS\system32\odbcint.dll
0x031E0000 - 0x031FE000         C:\Programmi\File comuni\Symantec
Shared\Script Blocking\scrauth.dll
0x03210000 - 0x03230000         C:\Programmi\File comuni\Symantec
Shared\Script Blocking\ScrBlock.dll
0x0FFD0000 - 0x0FFF8000         C:\WINDOWS\system32\rsaenh.dll
0x75C00000 - 0x75C6E000         c:\windows\system32\jscript.dll
0x73270000 - 0x732D7000         c:\windows\system32\vbscript.dll
0x73D40000 - 0x73E3E000         C:\WINDOWS\system32\MFC42.DLL
0x61E00000 - 0x61E0E000         C:\WINDOWS\system32\MFC42LOC.DLL
0x71CD0000 - 0x71CEC000         C:\WINDOWS\System32\actxprxy.dll
0x6D460000 - 0x6D470000
C:\Programmi\Java\j2re1.4.2_05\bin\npjpi142_05.dll
0x5F210000 - 0x5F227000         C:\WINDOWS\system32\OLEPRO32.DLL
0x6D330000 - 0x6D348000
C:\Programmi\Java\j2re1.4.2_05\bin\jpiexp32.dll
0x76EE0000 - 0x76F07000         C:\WINDOWS\system32\DNSAPI.dll
0x76F70000 - 0x76F78000         C:\WINDOWS\System32\winrnr.dll
0x75280000 - 0x7529E000         C:\WINDOWS\system32\wshbth.dll
0x6D3A0000 - 0x6D3B8000
C:\Programmi\Java\j2re1.4.2_05\bin\jpishare.dll
0x08000000 - 0x08139000
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\client\jvm.dll
0x03280000 - 0x03287000
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\hpi.dll
0x03420000 - 0x0342E000
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\verify.dll
0x03D40000 - 0x03D59000
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\java.dll
0x03D60000 - 0x03D6D000
C:\PROGRA~1\Java\J2RE14~1.2_0\bin\zip.dll
0x06910000 - 0x06A22000
C:\Programmi\Java\j2re1.4.2_05\bin\awt.dll
0x06A30000 - 0x06A81000
C:\Programmi\Java\j2re1.4.2_05\bin\fontmanager.dll
0x736D0000 - 0x73719000         C:\WINDOWS\system32\ddraw.dll
0x73B30000 - 0x73B36000         C:\WINDOWS\system32\DCIMAN32.dll
0x738B0000 - 0x73980000         C:\WINDOWS\system32\D3DIM700.DLL
0x6D310000 - 0x6D324000
C:\Programmi\Java\j2re1.4.2_05\bin\jpicom32.dll
0x6C2D0000 - 0x6C305000         C:\WINDOWS\System32\dxtrans.dll
0x07010000 - 0x0701F000
C:\Programmi\Java\j2re1.4.2_05\bin\net.dll
0x6D950000 - 0x6D95A000         C:\WINDOWS\System32\ddrawex.dll
0x6C310000 - 0x6C36A000         C:\WINDOWS\System32\dxtmsft.dll
0x08F70000 - 0x08F92000
C:\Programmi\Java\j2re1.4.2_05\bin\dcpr.dll
0x76270000 - 0x762E1000         C:\WINDOWS\System32\mshtmled.dll
0x72C90000 - 0x72C99000         C:\WINDOWS\system32\wdmaud.drv
0x72C80000 - 0x72C88000         C:\WINDOWS\system32\msacm32.drv
0x77BB0000 - 0x77BC5000         C:\WINDOWS\system32\MSACM32.dll
0x77BA0000 - 0x77BA7000         C:\WINDOWS\system32\midimap.dll
0x76BB0000 - 0x76BBB000         C:\WINDOWS\system32\PSAPI.DLL

Heap at VM Abort:
Heap
 def new generation   total 576K, used 386K [0x10150000, 0x101f0000,
0x108b0000)
  eden space 512K,  73% used [0x10150000, 0x101adc38, 0x101d0000)
  from space 64K,  17% used [0x101d0000, 0x101d2c70, 0x101e0000)
  to   space 64K,   0% used [0x101e0000, 0x101e0000, 0x101f0000)
 tenured generation   total 3112K, used 2644K [0x108b0000, 0x10bba000,
0x16150000)
   the space 3112K,  84% used [0x108b0000, 0x10b45078, 0x10b45200,
0x10bba000)  compacting perm gen  total 5120K, used 4945K [0x16150000,
0x16650000, 0x1a150000)
   the space 5120K,  96% used [0x16150000, 0x16624728, 0x16624800,
0x16650000)

Local Time = Sun Jan 30 21:39:24 2005
Elapsed Time = 3664
#
# The exception above was detected in native code outside the VM # #
Java
VM: Java HotSpot(TM) Client VM (1.4.2_05-b04 mixed mode) #

Bye,

-- 
Fabio Ruini
msn: f_ruini () hotmail com - icq: #2887596
e-mail: fabio.ruini () aliceposta it
web: http://www.webalice.it/fabio.ruini






Current thread: