Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
| Software | From | Fixed in |
|---|---|---|
| microsoft / ie | 6.0-sp1 | 6.0-sp1.x |
| microsoft / ie | 6.0-sp2 | 6.0-sp2.x |
| microsoft / internet_explorer | 6.0 | 6.0.x |
| microsoft / internet_explorer | 7.0-beta1 | 7.0-beta1.x |
| microsoft / internet_explorer | 7.0-beta2 | 7.0-beta2.x |