This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

IEv6 Race Condition Vuln

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/19521/
Release Date: 2006-04-04
Critical: Less critical
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 6.x
Description:
…The vulnerability is caused due to a race condition in the loading of web content and Macromedia Flash Format files (".swf") in browser windows. This can be exploited to spoof the address bar in a browser window showing a Flash file from a malicious web site.
NOTE: The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window.
The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. Other versions may also be affected.
Solution:
Disable Active Scripting support…"

:( :ph34r:
FYI…

- http://secunia.com/advisories/19521/
Last Update: 2006-04-06
Critical: Moderately critical ^
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 6.x

Exploit code is out!…

Secunia has constructed a test, which can be used to check if your browser is affected by this issue:
http://secunia.com/Internet_Explorer_Addre…erability_Test/
The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (March edition). Other versions may also be affected…
Solution:
Disable Active Scripting support.
2006-04-06: Added CVE reference. Added information about Internet Explorer 7 Beta 2 Preview being affected."

> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2006-1626

:ph34r: