| To: | bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk |
|---|---|
| Subject: | Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS) |
| From: | Alexander Sotirov <asotirov@determina.com> |
| Date: | Sun, 28 Jan 2007 21:58:42 -0800 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
| User-agent: | Thunderbird 1.5.0.9 (Windows/20061207) |
I thought that after the success of MoBB last year, fuzzing browsers will be
pointless, since all vendors would take care of the easily-found bugs before a
release. It turns out that I was wrong. I ran a very simple ActiveX fuzzer
against Vista and found a NULL pointer dereference bug in no time. The
vulnerable ActiveX control is on the pre-approved list in IE7, which makes the
bug easy to trigger with no security warnings and no user interaction.
Try this:
<script language="JavaScript">
obj = new ActiveXObject("giffile");
obj.bgColor;
</script>
MSRC said that this is a reliability bug and not a security issue, and it will
be fixed at some point in the future. I agree that DoS bugs against IE are not
very important (as long as skape doesn't drop any more vulns like MS06-051 :-),
but it's interesting that such a simple bug in such an obvious part of the IE7
attack surface was not discovered and fixed before the release.
See the full technical details at
http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html
More about fuzzers and ActiveX at
http://determina.blogspot.com/2007/01/fuzzing-shouldnt-work.html
Alexander Sotirov
Determina Security Research
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | MDPro 1.0.76 - Multiple Remote Vulnerabilities, adexior |
|---|---|
| Next by Date: | [OpenPKG-SA-2007.008] OpenPKG Security Advisory (cvstrac), OpenPKG GmbH |
| Previous by Thread: | MDPro 1.0.76 - Multiple Remote Vulnerabilities, adexior |
| Next by Thread: | [OpenPKG-SA-2007.008] OpenPKG Security Advisory (cvstrac), OpenPKG GmbH |
| Indexes: | [Date] [Thread] [Top] [All Lists] |