OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] IE8 crashes with simple HTML

From: Thierry Zoller (ThierryZoller.lu)
Date: Wed Aug 05 2009 - 05:00:41 CDT


Could reproduce, unhandled second chance read access violation in
mshtml!Ptls5::FsUpdateBottomlessPel+0x41d (FPO: [7,45,4])

Faulting Instruction:40af4234 cmp ecx,dword ptr [eax+18h]

Basic Block:
    40af4234 cmp ecx,dword ptr [eax+18h]
       Tainted Input Operands: eax, ecx
    40af4237 jne mshtml!ptls5::fsupdatebottomlesspel+0x47c (40af6cf7)
       Tainted Input Operands: ZeroFlag

--
http://blog.zoller.lu
Thierry Zoller

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/