New IE bug crashes browsers

A simple flaw in Internet Explorer 6.0 causes the browser to crash when it views pages containing malicious HTML code, a security researcher has found.

Although many DoS vulnerabilities such as this can lead to the discovery of more serious flaws after further research, AusCERT security researcher Jamie Gillespie said it's unlikely in this case.

"Its exploitable for the DoS, for sure, but not every DoS bug leads to execution of code," Gillespie told ZDNet Australia. "Going by what I can see so far, I don't believe it would be [fully] exploitable".

The Denial of Service (DoS) bug was disclosed on the bugtraq security mailing list, but at this stage, it's unclear if Microsoft has been kept in the loop.

"Going down the disclosure track, I wonder if this has been revealed to Microsoft or this guy has just posted it," Gillespie said.

If the bug turns out to be a simple DoS problem, then Microsoft aren't likely to be phased, but it could cause them headaches if the issue is found to be more serious. The software giant will most likely conduct its own research into the matter, says Gillespie.

"There needs to be research as to the cause of the bug, and if there's a fix present it must be regression tested to ensure the fixing of one bug doesn't introduce another more dangerous flaw," he added.

The bug is exploited through five lines of HTML code. A test conducted by ZDNet Australia  revealed that when embedded in a viewed page, the code causes all open Internet Explorer windows to close.

Unlike a buffer overflow, the glitch may turn out to be harmless -- the result of some sloppy programming.

-It doesn't look like a buffer overflow... if anything [the code is] not giving Internet Explorer information that it's expecting and that's what's causing the problem," Gillespie said.

Microsoft Australia was unable to comment at the time of writing.

Advertisement

Talkback 3 comments

    I think i may have this bug cause i can't get into any secured sites like, Hotmail and NetBank. Is there anyway to fix it? I gotta use Netscape now! :( And MSN Messenger doesn't work! :( Thanks ByeStephen James Pearson -- 21/04/03

    I think i may have this bug cause i can't get into any secured sites like, Hotmail and NetBank.

    Is there anyway to fix it?

    I gotta use Netscape now! :(

    And MSN Messenger doesn't work! :(

    Thanks Bye

    Since I downloaded MSIE 6 my system locks up everytime I use it. For weeks I searched the web for answers, tying all types of solutions, the last one being, dump IE 6, I couldn't get IE 5.5 so I down loaded Netscape and my system is running smooth again.Anonymous -- 15/06/03

    Since I downloaded MSIE 6 my system locks up everytime I use it. For weeks I searched the web for answers, tying all types of solutions, the last one being, dump IE 6, I couldn't get IE 5.5 so I down loaded Netscape and my system is running smooth again.

Add your opinion


Latest Videos

Blogs

  • Renai LeMay Datacentre disaster lessons
    As a system administrator, the health and status of your datacentre is at the forefront of your mind. But how often do you think about the needs beyond server status and bandwidth?
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • More blogs »

Tags

Back to top

Featured