Advertisement
Promo

Security threats Toolkit

New IE overflow exploit published

Joris Evers CNET News

Published: 21 Mar 2006 10:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is investigating a newly reported flaw in Internet Explorer 6 that could cause the browser to crash when viewing a malicious Web page, the company said on Monday.

Details of the security weakness in the Web browser were published on a popular security mailing list last week by researcher Michal Zalewski. "This might not come as a surprise, but there appears to be a very interesting and apparently very much exploitable overflow in Microsoft Internet Explorer," he wrote.

The flaw can be exploited by an attacker to crash IE, Secunia said in an advisory published on Monday. The vulnerability has been confirmed on a fully patched PC running IE 6 and Windows XP with Service Pack 2, the security monitoring company said. Secunia deems the issue "not critical."

Microsoft is investigating the issue, a company representative said in an emailed statement. "At this time, we are not aware of any attacks attempting to use the reported vulnerability," the representative wrote.

Once it completes its inquiry, Microsoft said, it may issue a security advisory or provide a patch through its monthly release process.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
85 out of 142 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters