Short Name |
HTTP:STC:IE:NESTED-OBJECT-TAG |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
Microsoft Internet Explorer Nested Object Tags |
Release Date |
2006/04/27 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects the download of nested Object tags in an HTML document. These tags can cause Internet Explorer to crash.
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This issue is due to a flaw in the application in handling nested OBJECT tags in HTML content. An attacker could exploit this issue via a malicious web page to potentially execute arbitrary code in the context of the currently logged-in user, but this has not been confirmed. Exploit attempts likely result in crashing the affected application. Attackers could exploit this issue through HTML email/newsgroup postings or through other applications that employ the affected component. Microsoft Internet Explorer 6 for Microsoft Windows XP SP2 is reportedly vulnerable to this issue; other versions may also be affected.