New IE bug crashes browsers

A simple flaw in Internet Explorer 6.0 causes the browser to crash when it views pages containing malicious HTML code, a security researcher has found.

Although many DoS vulnerabilities such as this can lead to the discovery of more serious flaws after further research, AusCERT security researcher Jamie Gillespie said it's unlikely in this case.

"Its exploitable for the DoS, for sure, but not every DoS bug leads to execution of code," Gillespie told ZDNet Australia. "Going by what I can see so far, I don't believe it would be [fully] exploitable".

The Denial of Service (DoS) bug was disclosed on the bugtraq security mailing list, but at this stage, it's unclear if Microsoft has been kept in the loop.

"Going down the disclosure track, I wonder if this has been revealed to Microsoft or this guy has just posted it," Gillespie said.

If the bug turns out to be a simple DoS problem, then Microsoft aren't likely to be phased, but it could cause them headaches if the issue is found to be more serious. The software giant will most likely conduct its own research into the matter, says Gillespie.

"There needs to be research as to the cause of the bug, and if there's a fix present it must be regression tested to ensure the fixing of one bug doesn't introduce another more dangerous flaw," he added.

The bug is exploited through five lines of HTML code. A test conducted by ZDNet Australia  revealed that when embedded in a viewed page, the code causes all open Internet Explorer windows to close.

Unlike a buffer overflow, the glitch may turn out to be harmless -- the result of some sloppy programming.

-It doesn't look like a buffer overflow... if anything [the code is] not giving Internet Explorer information that it's expecting and that's what's causing the problem," Gillespie said.

Microsoft Australia was unable to comment at the time of writing.

Advertisement

Talkback 3 comments

    I think i may have this bug ca ...Stephen James Pearson -- 21/04/03

    I think i may have this bug cause i can't get into any secured sites like, Hotmail and NetBank.

    Is there anyway to fix it?

    I gotta use Netscape now! :(

    And MSN Messenger doesn't work! :(

    Thanks Bye

    Since I downloaded MSIE 6 my ...Anonymous -- 15/06/03

    Since I downloaded MSIE 6 my system locks up everytime I use it. For weeks I searched the web for answers, tying all types of solutions, the last one being, dump IE 6, I couldn't get IE 5.5 so I down loaded Netscape and my system is running smooth again.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured