New IE bug crashes browsers

A simple flaw in Internet Explorer 6.0 causes the browser to crash when it views pages containing malicious HTML code, a security researcher has found.

Although many DoS vulnerabilities such as this can lead to the discovery of more serious flaws after further research, AusCERT security researcher Jamie Gillespie said it's unlikely in this case.

"Its exploitable for the DoS, for sure, but not every DoS bug leads to execution of code," Gillespie told ZDNet Australia. "Going by what I can see so far, I don't believe it would be [fully] exploitable".

The Denial of Service (DoS) bug was disclosed on the bugtraq security mailing list, but at this stage, it's unclear if Microsoft has been kept in the loop.

"Going down the disclosure track, I wonder if this has been revealed to Microsoft or this guy has just posted it," Gillespie said.

If the bug turns out to be a simple DoS problem, then Microsoft aren't likely to be phased, but it could cause them headaches if the issue is found to be more serious. The software giant will most likely conduct its own research into the matter, says Gillespie.

"There needs to be research as to the cause of the bug, and if there's a fix present it must be regression tested to ensure the fixing of one bug doesn't introduce another more dangerous flaw," he added.

The bug is exploited through five lines of HTML code. A test conducted by ZDNet Australia  revealed that when embedded in a viewed page, the code causes all open Internet Explorer windows to close.

Unlike a buffer overflow, the glitch may turn out to be harmless -- the result of some sloppy programming.

-It doesn't look like a buffer overflow... if anything [the code is] not giving Internet Explorer information that it's expecting and that's what's causing the problem," Gillespie said.

Microsoft Australia was unable to comment at the time of writing.

Advertisement

Talkback 3 comments

    I think i may have this bug ca ...Stephen James Pearson -- 21/04/03

    I think i may have this bug cause i can't get into any secured sites like, Hotmail and NetBank.

    Is there anyway to fix it?

    I gotta use Netscape now! :(

    And MSN Messenger doesn't work! :(

    Thanks Bye

    Since I downloaded MSIE 6 my ...Anonymous -- 15/06/03

    Since I downloaded MSIE 6 my system locks up everytime I use it. For weeks I searched the web for answers, tying all types of solutions, the last one being, dump IE 6, I couldn't get IE 5.5 so I down loaded Netscape and my system is running smooth again.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured