CVE-2007-3550: Code Injection
DISPUTED Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3550?
CVE-2007-3550 has been classified as a denial of service vulnerability.
How do I fix CVE-2007-3550?
There is no specific fix for CVE-2007-3550, but upgrading to a newer version of Internet Explorer or applying security updates can mitigate the risk.
What versions of Internet Explorer are affected by CVE-2007-3550?
Internet Explorer versions 6.0 SP1, 6.0 SP2, and 7.0, including its beta versions, are affected by CVE-2007-3550.
What impact does CVE-2007-3550 have on web services?
CVE-2007-3550 can lead to website suppression and resource consumption, effectively disrupting web services.
Is CVE-2007-3550 exploitative for remote attackers?
Yes, CVE-2007-3550 allows remote attackers to exploit the vulnerability using JavaScript to fill Zones with arbitrary domains.