ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Unpatched IE flaw allows remote attacks

Ingrid Marson ZDNet.co.uk

Published: 20 Jul 2005 16:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in Microsoft Internet Explorer's image rendering capabilities may allow attackers to execute code remotely, according to security experts.

Security consultant and author Michal Zalewski has found a number of possible flaws in the way IE handles JPEG images, one of which he claims could be exploited for remote arbitrary code execution — a type of attack that is generally categorised as critical by security vendors.

Four proof-of-concept images that can exploit these flaws have been made available by Zalewski. Each of these crashes IE 6, the latest version of Microsoft's browser, even if it has been patched with Service Pack 2. Previous versions of IE may also be affected, said SecurityFocus. Two of the exploit images also cause memory and CPU problems.

Zalewski did not report this bug to Microsoft before publishing it, due to the problems he claims to have experienced with the software giant's bug-reporting process.

"It is my experience that reporting and discussing security problems with Microsoft is a needlessly lengthy process that puts too much burden and effort on the researcher's end, especially if you just have a crash case, not a working exploit; hence, they did not get an advance notice," said Zalewski in a posting on security site Neophasis.

"Microsoft is investigating new public reports of possible vulnerabilities in Internet Explorer, but we have not been made aware of attacks," a spokesperson said. "Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. Microsoft is concerned that this new report of possible vulnerabilities in Internet Explorer was not disclosed responsibly, potentially putting computer users at risk."

Earlier this week, another image-processing security vulnerability that affected both IE and MSN Messenger surfaced. That bug was caused by vulnerability in the way the applications handle International Color Consortium Profiles, but that was fixed by Microsoft in their last set of patches.

More information on the flaws can be found on the SecurityFocus Web site, under bug number 14282 and 14284.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
102 out of 194 people found this useful


Full Talkback thread

1 comment

  1. It doesn't under W2K Paul J White

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Solutions Design Manager / Senior Solutions Design Manager

Cognos V8 and / or Hyperion Essbase (System 9) and will be proactive in seeking to exploit these for business benefit. It is the responsibility of ...

Reporting Analyst Needed - London

My client, a global media company, requires a reporting analyst to help model data sources to support a reporting application. In addition detailed ...

Software Development Project Manager (Project Manager) Oxfordshire

This represents an immense opportunity for a seasoned Project Manager to work in a high profile and innovative environment where there is ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.