urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
Link | Tags |
---|---|
http://www.security-protocols.com/advisory/sp-x23-advisory.txt | |
http://www.securityfocus.com/bid/16463 | vdb entry exploit |