NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Windows

Windows


Michal Zalewski Announces A New Bug for Internet Explorer

Rated by Secunia as being "highly critical"

By Tudor Raiciu, Technology and Science Editor

26th of April 2006, 14:53 GMT

Adjust text size:


Michal Zalewski, the researcher who announced in March an Internet Explorer vulnerability whose exploitation could crash the browser, has some news for Microsoft and the company's security experts won't be too pleased with them.

The bug comes not long after Microsoft plugged numerous security holes with the April patches.

Secunia has rated the bug as being "highly
critical" (the last but one alert level used by the security company) and has warned that its successful exploitation could compromise a system.

The vulnerability is caused by an error in the processing of certain sequences of nested "object" HTML tags. This can be exploited to corrupt memory by tricking a user into visiting a malicious web site. A successful attempt allows execution of arbitrary code.

The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.

A Microsoft spokesman was quoted by eWeek as saying that the initial investigation revealed the bug would most likely result in the browser closing unexpectedly or failing to respond. The Redmond company also criticized the researcher for rushing into posting information about it before there was a patch.

In other April patching news, Stephen Toulouse announced yesterday that a new version of the security bulletin MS06-015, which caused some incompatibilities, was ready and that Automatic Update would automatically detect if its installation was necessary.
Read by 2,052 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.1/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Gives Companies Another 60 Days to Update Their Sites for the New IE

New Wave of IE Malware

Microsoft Update Party on March, April 11

The Internet Explorer Updates Are Available for Download

Microsoft's April 11 Patches Have Issues

Microsoft Releases an Updated Version of Internet Explorer Beta 2

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM