First published: Fri Dec 31 2004(Updated: )
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2434 has a severity rating that indicates it allows remote attackers to cause a denial of service, specifically crashing Internet Explorer.
To fix CVE-2004-2434, it is recommended to update Microsoft Internet Explorer to a version that is not affected, or apply the relevant patches provided by Microsoft.
CVE-2004-2434 specifically affects Microsoft Internet Explorer version 6.0 Service Pack 1.
Yes, CVE-2004-2434 can be exploited remotely by crafting a link that triggers a browser crash when the user interacts with it.
The impact of CVE-2004-2434 on users is a denial of service which results in the browser crashing when attempting to save a maliciously crafted link.