[ news_security_news ] IE7 Glitches
John Stith Staff Writer
2006-02-06
Insider Reports RSS Feed
Fortunately, Betas are sent out to find problems. Microsoft put out Internet Explorer 7 Beta2 Preview (IE7B2P) for just that reason. They weren't disappointed because as IE7 got used, it opened up like a rotten log and bugs came flying in all directions.
Cybersecurity researcher Tom Ferris did some digging around in IE7B2 and found what he considers to be medium risk flaws. He's produced a proof of concept demo to show how the program is vulnerable to denial of service (DoS) attacks.
Microsoft's IE blog confirmed the bug and said they'd already spotted the bug in their own code review. They said on their blog:
This bug had already been found during our code review and analysis that is a mandatory part of our development process; it was scheduled to be fixed before our next public release. We do not believe this bug is easily exploitable, and as an extra defense, the /GS flag also catches the overrun. This is a compiler flag that tells Windows to watch for some classes of buffer overflows. If Windows sees a problem, it kills the application, in this case IE, instead of running the exploit code. While this is certainly not our primary line of protection, it does offer defense-in-depth to help keep our customers secure.
At this time, we are not aware of any active exploits taking advantage of this bug. We will continue to monitor the situation and evaluate our response.
This hasn't been the only problem with IE7B2P. There was something of a problem that cause IE7B2P to crash when certain website showed up. Some other problems included issues with McAfee security software. Fortunately, this is just a beta and mistakes are expected. One can only hope most of the problems are corrected by the time the product hits its final release.
Add to | DiggThis| Yahoo My Web
About the Author:
John is a staff writer for SecurityProNews covering cyber security.
More news_security_news Articles
Insider Reports RSS Feed
|
|