TechTalkz.com Logo

Go Back   TechTalkz.com Technology & Computer Troubleshooting Forums > Tech World > Computer Security

Notices

Reply
 
Thread Tools Display Modes
Old 24-03-2006, 12:53 PM   #1
Junior Member (25+)
 
MaYeR's Avatar
 
Join Date: Feb 2006
Posts: 77
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 6 MaYeR is a jewel in the roughMaYeR is a jewel in the roughMaYeR is a jewel in the roughMaYeR is a jewel in the rough
Cool Microsoft Confirms New Critical IE Flaw

Microsoft has confirmed the existence of a critical Internet Explorer flaw that could put millions of IE users at risk of code execution just by visiting a malicious Web site. The flaw was first reported this week by Danish security firm Secunia.

According to the firm's advisory, the flaw exists in how Internet Explorer interprets the "createTextRange()" method used for radio button controls in HTML forms. From there, the flaw can be exploited to allow program flow to be redirected to the heap.

When this occurs, the attacker can then exploit the vulnerability to execute code on an affected computer. Secunia recommends that active scripting support be disabled, an action Microsoft's Security Response Center also suggested.

The flaw has been confirmed to exist on a fully patched system with Internet Explorer 6 and Windows XP Service Pack 2. The vulnerability also affects the Beta 2 Preview of Internet Explorer, although the refresh provided at MIX 06 this week is apparently not affected.

News of the flaw came a day after a security researcher discovered another bug in the market-leading browser. That issue, while more of a nuisance than an actual security threat, causes IE to crash when visiting a malicious Web site.

The problem is caused by an array boundary error in the handling of HTML tags with multiple event handlers. The vulnerability can be exploited to cause Internet Explorer 6 to crash through a specially crafted HTML tag with 94 or more event handlers.
__________________
Mayer
MaYeR is offline   Reply With Quote
Reply

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft confirms Vista SP1 by Q1 2008, and XP SP3 by H1 2008 ! anandk Windows Vista 1 29-08-2007 11:49 PM
Microsoft patches Vista flaw in Windows Client/Server Run-time Subsystem (CSRSS) process Strider Windows 98/2000/ME/XP/2003/Vista 0 11-04-2007 11:55 PM
Microsoft Issues Three Critical Patches Strider Computer Security 0 13-12-2006 11:36 AM
Hackers Can Crack Symantec Norton Antivirus - Critical Flaw AiM Computer Security 7 28-05-2006 08:19 PM
Microsoft Releases Critical IE Patch smartjean4u Technical Discussions 0 12-04-2006 03:30 PM



New To Site? Need Help?

All times are GMT +5.5. The time now is 07:35 PM.


vBulletin, Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO
Copyright © 2005-2009, TechTalkz.com. All Rights Reserved - Privacy Policy
Valid XHTML 1.0 Transitional