New Security Flaw Discovered in IE

By Ed Oswald | Published September 16, 2005, 11:45 AM

Security firm eEye released a notice on Thursday saying it had discovered a new flaw within Internet Explorer on both Windows XP and XP SP2. According to the notice, "A vulnerability in default installations of the affected software could allow for remote code execution."

Windows XP SP2 was touted as a much more secure version of Microsoft's flagship operating system. However, hackers have still found ways around the new security features, and flaws continue to pop up. Microsoft has been alerted to the problem, but as standard practice eEye will not release details of the vulnerability until it is patched or publicly acknowledged by Microsoft.

Comments

View comments by with a score of at least

is this news? or just the weekly list of flaws? :P

Important System Message ==> Browser used to view and enter this message = FIREFOX :P

Score: 0

|

Microsoft Sam is repairing your internet code deficiencies nowwwwwww.

Score: 0

|

Score: 0

|

What Else Is New.

Score: 0

|

edit: repeat of someone elses quote

Score: 0

|

*sigh*...MS will fix it, but will this ever end? It's the same bloody thing over and over again; remote code execution. Of course, there's some sniveling, overweight, snot-nose punkass loser ready to exploit it at the drop of a hat. For all you crackers out there, @#&% you! You ought to be disgusted with yourselves. Where in Sam hell is your consience!? Anyways, I digress and must keep my emotions in check. After all, it's to be expected; we've been in the midst of a downward, spiralling out of control regression of humankind since around the late 80's. It's appropriately known as Devolution.

Score: 0

|

Not a surprise.

Score: 0

|

In other news, smoking is bad for you.

Patch for IE flaw:
http://www.mozilla.org/products/firefox/

Score: 0

|

didnt firefox just fix a flaw, ya they did

Score: 0

|

Ahh, but it's a minor one, and FF isn't tightly tied into your OS.

Score: 0

|

Well apparently "Extreemely Critical" meens "a minor one" when refering to FF...

Score: 0

|

lol. I was about to reply with the same comment.

Score: 0

|

Have fun rebooting your entire infrastructure when MS releases it's next browser patch. There goes your uptime!

Score: 0

|

That's what clusters and load balancers are for. ;-)

Score: 0

|

Yes, Firefox fixed a IDN flaw a few days after it was reported.......the key word is fixed, and in a timely manner.......Microspud will fix this some time around X-mas probably

Score: 0

|

Actually, it's just a work-around that disables the feature alogether for now. They're still working on a "fix."

That being said, they were quick to provide at least a temporary solution.

Score: 0

|

They issued a new version of Firefox (1.0.7) that fixes the flaw.

Score: 0

|

Yup. MS, you need to fix your existing patches and get one ready for this issue too...it would be very unwise at this point for MS to wait until next patch Tuesday, regardless of original plans, as yet another flaw is revealed.

Note to Ed Oswald: Based on the first two sentences in your last paragraph (which is irrelevant at this time BTW), it's safe to say you still have issues with MS. But with SP2 being over a year old now--get over it!!!

Score: 0

|

"it would be very unwise at this point for MS to wait until next patch Tuesday"
after every patch tuesday, there is a hacks wednesday

Score: 0

|

Maybe you guys would be interested in reading this article I found on Slashdot.org.

prostoalex writes "With Firefox market share reaching a substantial level, is the popular Internet browser becoming a security nightmare for IT administrators? George Ou takes a look at the hard numbers. From the article: 'From March 2005 to September 2005 10 vulnerabilities were published for Microsoft Internet Explorer, 40 for Mozilla Firefox. In April-September timespan there were 6 exploits for MSIE, 11 for Firefox. Conclusion? As you can see, the facade that Firefox is the cure to the Internet Explorer security blues is quickly fading. It just goes to prove that any popular software worth hacking that has security vulnerabilities will eventually have to deal with live working exploits. Firefox mostly managed to stay under the radar from hackers before April of 2005.'"

Maybe you should stop bashing MS, and understand your browser is not perfect.... and nor is IE, thats life nobody's perfect, and none will every be so move on and stop whining.

Score: 0

|

With the only difference that there is usually a fix for crititcal flaws available within 48Hours while MS sometimes takes up to 6 months to poorely avoid a flaw by simply removing a functionality (D&D exploit anyone?!) With the upcoming autoupdating capabilities of FF1.5 hotfixes _can_ be done in background without any user action. Oh and by the way, do you realy think that one could compare the numbers of NEWLY discoverd flaws of a AGED product to the ones of a totaly NEW one. Try adding all IE bugs since 6.0 (actually since 5.0 since there are some minor flaws that are still not fixed) and all FF bugs since 1.0, imho those numbers would be way more conclusive.

Score: 0

|

Thats not realistic either, 5.0/6.0 have been out wayy longer than FF 1.0. There is really no equivelent comparison as when IE 5.0 released, security was not the biggest concern and less vulnerabilities were found/fixed.

And actually FF has removed features as bugfixes or put advisories to do so a lot more often than MS has. The only time I can remember MS doing this is with the login in url issue (http://user:pass@host).

Maybe a fair way to do this would be compare all the critical bugs released only.

Oh and btw, fairness does not actually matter now that I think about it. Once FF got to 1.0, it was advertised for usage and as more secure, that means it should be. The question at hand is whether it is currently more secure, not whether after they have as much time as IE in the market they are secure.

Score: 0

|

I agree.
Firefox and it's supporters claim to fame is "Security". I hold it to a higher standard for that reason and because, as the fans are prone to say, it is not tied to the OS, so fixes only need address the browser.
Still, slow or temp patches/workarounds are the case many times.

But, just where do I need to go to have all the 'problems' others find/report? I live in China, visit 'dangerous' sites, download and install lots of things.

I've yet to be hijacked, compromised. etc.

BTW- I use FF 1.06, didn't like I.E. 7 because of the lack of Adblock. Otherwise, I'd stick to IE.

Score: 0

|

Considering that Microspud has cancelled "Patch Tuesdays" I dont think this is going to happen

Score: 0

|

ahh, but thats what Google toolbar, Maxathon and Avant are for.

Score: 0

|

I am getting really tired of both of these arguments. FireFox users keep saying "fixes are quick" or "fixes come withing 48 hours" or "with it being open source the users fix it rapidly". The hassle is the same for users who have to constantly go out and get FF or IE fixes and install them. IE vs FF is like American politics; each side reads the same things and interprets them completely differently, and each side thinks the other is moronic. Use what you want to use and I'll use what I want to use.

I think it has already been shown that the higher the market share there is a sharp increase reported bugs and flaws, simply because the number of users is greater and more flaws are located. When FireFox first came out security flaws were unheard of, and everyone thought it was the IE killer because it was more secure. I'm sure with every release of FireFox there will be new flaws discovered and even more flaws that existed in older versions. This is what happens when you add new features and functionality.

Unless you are a programmer, and I mean a real programmer, not just a programmer at home, you really should not judge. It is extremely difficult to create bug free software when there are real deadlines and a budget. Couple those things, with the complexities and intricacies of coding an operating system or completely secure internet browser, and no one would be perfect.

As one previous poster pointed out, the problem is all of these idiots that sit in their parents basements drinking Mt. Dew, eating Ramen, chatting to their internet girlfriends (or boyfriends, since I don't want to be sexist haha) and hammering at software to find security flaws.

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.