Latest YouTube Video

Friday, November 25, 2016

[FD] Microsoft Internet Explorer 11 MSHTML CGeneratedContent::HasGeneratedSVGMarker type confusion

Throughout November, I plan to release details on vulnerabilities I found in web-browsers which I've not released before. This is the eighteenth entry in that series. Unfortunately I won't be able to publish everything within one month at the current rate, so I may continue to publish these through December and January. The below information is available in more detail on my blog at http://ift.tt/2fLRgdr. There you can find a repro that triggered this issue, reversed snippets from the vulnerable code and more details in addition to the information below. Follow me on http://twitter.com/berendjanwever for daily browser bugs. MSIE 11 MSHTML CGeneratedContent::HasGeneratedSVGMarker type confusion ======================================================= (The fix and CVE number for this issue are unknown) Synopsis

Source: Gmail -> IFTTT-> Blogger

No comments: