main

Microsoft Confirms IE6+/IE7 Security Bug

Mr magoo   on 23 March 2006 - 21:25 · 5 comments & 3560 views

Advertisement (Why?)
The Microsoft Internet Explorer team have confirmed a serious bug that can crash IE when users visit affected websites.

The problem relates to the way the browser handles the createTextRange() function and affects all versions (IE6.x XP SP2 fully patched, IE7 beta). The bug was disclosed publicly last weekend before Microsoft were able to patch the problem.

Lennart from the MSRC blog advised " Our initial investigation has revealed that if you turn off Active Scripting, that will prevent the attack as this requires script. Customers who use supported versions of Outlook or Outlook Express aren’t at risk from the email vector since script doesn’t render in mail (being read in the restricted sites zone)." He said a security advisory would be released in the coming days.

A Microsoft official recently chided Apple for their lack of a public Security Czar, and was (rightly) criticized for hypocrisy. However, Microsoft, for all their faults (and bugs) do appear to be making better efforts to publicize problems and deal with them in a timely matter. As Blogger in Chief Robert Scoble would say, blogs are about conversations - and it's good to see the security team, arguably one of the most important at Microsoft, getting more involved with their customers.

View: Microsoft Security Response Center Blog




Post a comment · Send to friend Comments · There are 5 additional comments
#1 MightyJordan on 23 Mar 2006 - 21:34
This does sound bad. If someone could make a list of the affected sites that would help everyone here a lot.
#2 madnuke on 23 Mar 2006 - 21:43
Thank god my story made the main page! This is serious.
#3 thenay on 23 Mar 2006 - 22:40
This doesn't affect the newest build of IE7, someone posted a link on the forums and in Firefox and Opera a girl with boxing gloves showed. On the old IE7 build it crashed my browser, but with the newest build it doesn't it shows the girl.
#4 D.V on 23 Mar 2006 - 23:18
i suppose its good that they are now taking a effort. it doesnt really concern me though, as i only use ie to test the compatibilty of my designs. but its no doubt good news for many.

btw, hypocrisy is spelled wrong.
#5 pandr on 24 Mar 2006 - 18:45
The latest IE7 beta2 build released on 20 March is not affected by these vulnerabilities
http://blogs.technet.com/msrc/default.aspx
If you're using the new refresh of the IE7 Beta 2 Preview announced at Mix06, then you are not affected by the public report. You can download the preview at " target="_blank">http://www.microsoft.com/windows/ie/ie7/default.msp

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)