From: Georgi Guninski To: BUGTRAQ@NETSPACE.ORG Subject: MSIE buffer overrun Date: 20 марта 1998 г. 19:05 Microsoft Internet Explorer 4.0 (don't know for other versions) can be crashed and eventually made execute arbitrary code with a little help of the tag. The following: opens a dialog box and closes IE 4.0. It seems that the long file extension causes stack overrun. The stack is smashed - full with our values, EIP is also ours and CS=SS. So probably a string could be constructed, executing code at the client's machine. Solution: Do not browse hostile pages. To try this: http://www.geocities.com/ResearchTriangle/1711/msie.html Georgi Guninski http://www.geocities.com/ResearchTriangle/1711 -----------------------cut here and save as crashmsie.html--------------------- Trying to crash IE 4.0 40 80 160 170 180 190 200