Vulnerabilities > CVE-2005-1791 - Denial of Service vulnerability in Microsoft IE 6.0

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
high complexity
microsoft

Summary

Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenario in which an attacker can trigger this behavior, then perhaps this issue should not be included in CVE.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 13798 CVE(CAN) ID: CVE-2005-1791 Microsoft Internet Explorer是微软发布的非常流行的WEB浏览器。 Microsoft Internet Explorer中存在的漏洞可能导致URLMON.DLL崩溃。 起因是Internet Explorer无法处理向受限站点区中添加特制的URL。如果要导致崩溃,URL必须以数字和逗点开始(类似于IP地址),但不必以类似于IP地址结束。 Microsoft Internet Explorer 6.0 SP2 临时解决方法: 如果您不能立刻安装补丁或者升级,NSFOCUS建议您采取以下措施以降低威胁: * 不要向任何区域添加上述URL。 厂商补丁: Microsoft --------- 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: <a href=http://www.microsoft.com/windows/ie/default.asp target=_blank>http://www.microsoft.com/windows/ie/default.asp</a>
idSSV:4150
last seen2017-11-19
modified2008-10-05
published2008-10-05
reporterRoot
titleMicrosoft Internet Explorer受限站点区畸形URL拒绝服务漏洞