Watch out there's an IE bug about
You've been iFramed
Posted in Enterprise Security, 4th November 2004 21:36 GMT
Free whitepaper – The starter PKI program
Microsoft's ubiquitous IE web browser software became the subject of yet another security flap this week.
The latest buffer overflow vulnerability could be used to inject hostile code into vulnerable systems, security clearing house US CERT warned yesterday.
The flaw stems from a bug in the way particular versions of IE process certain attributes in the IFRAME HTML tag. IE6 on Win XP SP1 and Win 2000 are both vulnerable.
But Win XP SP2 is safe from what Secunia describes as an "extremely critical" bug. It warns that a working exploit has been published.
Secunia advises users to either use Win XP SP2 or to try an alternative browser. US CERT reckons disabling active scripting might be enough. ®
Related stories
A bumper crop of browser glitches
Undead IE bug rises from grave
Seven critical in MS October patch batch
XP SP2 glitches to trip up one in 10 upgrades - report
WinXP SP2 = security placebo? (review)


Hosted security IT manager's guide
Securing your Apache web server with a Thawte digital certificate
Vulnerability management buyer's checklist
Email continuity
Google cloud told to encrypt itself
Chinese firm hits back at cyberspy claims
BlockMaster SafeStick hardware-encrypted USB drive