Microsoft has just released a fix for an issue I reported to them on December 4th, 2008. A simple repro can be found here.
Though I did not investigate the issue, it appears to be similar to MS05-20: it is triggered by having JavaScript running in one window create and delete EMBED elements with existing mime-types in another window in rapid succession. Because each window is running in its own thread in MSIE, the code must be thread-safe for two windows to interact correctly. This issues appears to be a re-entrancy problem that causes one thread to access data after that data was freed by another thread.
Quick links
Search this site
-
Categories
- ASCII Art (2)
- Browsers (13)
- Debugging (1)
- Funny (2)
- Popups (2)
- Google (8)
- Imagine Cup (7)
- Instant Messaging (1)
- Live Messenger (1)
- MediaWiki (2)
- notepad++ (1)
- Programming Languages (18)
- Registry (3)
- Security (9)
- Uncategorized (4)
- Video (1)
- YouTube (1)
Tags
2008 Apple Art ASCII chrome coding completion Contest ctrl+enter explorer FAIL fractal function function list Google Greasemonkey Guardian of Eden hl iGoogle Imagine Cup JavaScript JavaScript demo Mandelbrot Julia 256b JavaScript script BATCH HTML Chimera JSSh Language mandelbrot Microsoft n++ notepad++ optimization Paris php plugin quicktext regedit Registry Safari Search Security Shellcode stack StumbleUpon suggestion Vulnerability xss-
Recent Posts
-
Archives







