Computer Security
[EN] securityvulns.ru
no-pyccku





MS Outlook javascript parsing bug




MS Outlook javascript parsing bug





=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

   Date: Вт, 09 ноя 1999  20:47:20
  От: Mikael Olsson <mikael.olsson@ENTERNET.SE>
Кому: VULN-DEV@SECURITYFOCUS.COM
Тема: MS Outlook javascript parsing bug
--------------------------------------------------------------------------------


It seems that MS Outlook 8.5.5104.6 screws up when displaying the
following string in a mail message:

<javascript:location.reload()>

Note that you do NOT need to click it, just displaying the mail
message will crash Outlook.

The results are completely unpredictable, everything from hanging,
crashing or complaining about not being able to display a
particular font or complaining about being out of memory?!?!?!

Anyone care to do anything fun with it other than spam mailing
people to create a big 'ole DoS? :-)

Just my $.02
/Mike

--
Mikael Olsson, EnterNet Sweden AB, Box 393, S-891 28 ЦRNSKЦLDSVIK
Phone: +46-(0)660-105 50           Fax: +46-(0)660-122 50
Mobile: +46-(0)70-248 00 33
WWW: http://www.enternet.se        E-mail: mikael.olsson@enternet.se


About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru