Vulnerability Description
Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Ie | 6.0 |
| Microsoft | Internet Explorer | 6.0 |
Related Weaknesses (CWE)
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064326.html
- http://osvdb.org/45814
- http://securityreason.com/securityalert/2855
- http://www.secniche.org/advisory/Internet_Dos_Adv.pdfPatch
- http://www.securityfocus.com/archive/1/472651/100/0/threaded
- http://www.securityfocus.com/archive/1/473662
- http://www.securityfocus.com/archive/1/485536/100/0/threaded
- http://www.securityfocus.com/bid/24744Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35455
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064326.html
- http://osvdb.org/45814
- http://securityreason.com/securityalert/2855
- http://www.secniche.org/advisory/Internet_Dos_Adv.pdfPatch
- http://www.securityfocus.com/archive/1/472651/100/0/threaded
- http://www.securityfocus.com/archive/1/473662
FAQ
What is CVE-2007-3550?
CVE-2007-3550 is a vulnerability with a CVSS score of 7.8 (HIGH). Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service...
How severe is CVE-2007-3550?
CVE-2007-3550 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3550?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Ie, Microsoft Internet Explorer.