Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Windows

May 3rd, 2006, 10:36 GMT · By Tudor Raiciu

Internet Explorer 6: The Bug that Leads to Another... Bug

SHARE:

Adjust text size:


The analysis of a recent Internet Explorer 6 vulnerability, discovered by Michael Zalewski, had revealed another security hole in the world's most popular browser.

According to News.com, it was initially believed that the new bug, found by Andreas Sandblad of Secunia, was just another version of the one found by Zalewski, but Microsoft straightened
things out and said that there two different problems.

"During analysis, Secunia discovered a variant of this vulnerability and confirmed code execution on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2.", Secunia initially wrote.

The security company has rated the bug as being "highly critical" (the last but one alert level used by the security company) and has warned that its successful exploitation could compromise a system.

The vulnerability is caused by an error in the processing of certain sequences of nested "object" HTML tags. This can be exploited to corrupt memory by tricking a user into visiting a malicious web site.

Although the two bugs are separate, it seems that they are both caused by the same processing error.

TELL US WHAT YOU THINK:

2,798 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Michal Zalewski Announces A New Bug for Internet Explorer

Microsoft Releases an Updated Version of Internet Explorer Beta 2

Google Feels Threatened by Internet Explorer 7

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM