The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ie | Microsoft | 6.0 (including) | 6.0 (including) |
Ie | Microsoft | 6.0-sp1 (including) | 6.0-sp1 (including) |