Project

General

Profile

Actions

Bug #18970

closed

Symantec Client Firewall reports HTTP MS IE Object Element Data DoS attack and blocks

Added by Wolfgang Endhammer over 16 years ago. Updated over 16 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2008-06-17
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.2
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Since Version 4.2.0 Symantec Client Friewall reports HTTP MS IE Object Element Data DoS attack and blocks Webaddress for 30 minutes

The Symantec Error Report is:

HTTP MS IE Object Element Data DoS
Severity: Medium

This attack could pose a moderate security threat. It does not require immediate action.

Description

This signature detects attempts to exploit a vulnerability in Microsoft Internet Explorer which allows an attacker to issue a denial of service attack on the victim host Internet Explorer Web browser.

Additional Information

A denial of service vulnerability has been reported in Microsoft Internet Explorer. This vulnerability is related to how the browser interprets properties of Object elements. The Object element is normally used to specify an external object to invoke such as an ActiveX component, Applet, etc.

This condition may occur when a malicious web page specifies an Object element with a data property that has a value of "?" or "#" in addition to specifying a type property that refers to an image type (such as "image/gif"). The vulnerability will reportedly cause the browser to crash due to an infinite loop.

Affected:

Microsoft Internet Explorer 6.0, 6.0 SP1

Response

Upgrade to the latest version of Microsoft Internet Explorer and apply all available patches.

Possible False Positives

There are no known conditions for false positives associated with this signature.

(issue imported from #M8733)


Files

typo3.pcap (754 KB) typo3.pcap Administrator Admin, 2008-06-17 23:11
test_with internet.pcap (197 KB) test_with internet.pcap Administrator Admin, 2008-06-19 09:09
server_firewall_off.pcap (185 KB) server_firewall_off.pcap Administrator Admin, 2008-06-19 09:10
client_firewall_off.pcap (183 KB) client_firewall_off.pcap Administrator Admin, 2008-06-19 09:10
Actions

Also available in: Atom PDF