Version: 2008
  • On TechRepublic: Five super-secret features in Windows 7

July 21, 2005 4:12 PM PDT

Unpatched IE flaws reported

  • 8 comments
A flaw in Microsoft Internet Explorer's image rendering capabilities may allow attackers to execute code remotely, a security expert has warned.

Michal Zalewski, a security consultant and author, said he has found a number of possible flaws in the way the Web browser software handles JPEG images. Zalewski said that one of the flaws could be exploited for remote arbitrary code execution, a type of attack that is generally categorized as "critical" by security vendors.

Four proof-of-concept images that aim to exploit these flaws have been posted on the Web by Zalewski. Each of these has the potential to crash IE 6, the latest version of Microsoft's browser, even if it has been patched with Service Pack 2. Previous versions of IE may also be affected, according to a SecurityFocus posting. Two of the exploit images also cause memory and CPU problems.

Zalewski said he did not report this bug to Microsoft before publishing it, due to the problems he claims to have experienced with the software giant's bug-reporting process.

"It is my experience that reporting and discussing security problems with Microsoft is a needlessly lengthy process that puts too much burden and effort on the researcher's end, especially if you just have a crash case, not a working exploit; hence, they did not get an advance notice," said Zalewski in a posting on security site Neophasis.

"Microsoft is investigating new public reports of possible vulnerabilities in Internet Explorer, but we have not been made aware of attacks," a representative for the software maker said. "Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. Microsoft is concerned that this new report of possible vulnerabilities in Internet Explorer was not disclosed responsibly, potentially putting computer users at risk."

Earlier this week, another image-processing security vulnerability that affected both IE and MSN Messenger surfaced. That bug was caused by a flaw in the way the applications handle International Color Consortium Profiles, but that problem was fixed by Microsoft in its last set of patches.

More information on the flaws can be found on the SecurityFocus Web site, under bug number 14282 and 14284.

Ingrid Marson of ZDNet UK reported from London.

See more CNET content tagged:
SecurityFocus, flaw, security consultant, Microsoft Internet Explorer, Microsoft Internet Explorer 6

Add a Comment (Log in or register) (8 Comments)
  • prev
  • 1
  • next
Another day ... Another FLAW
by July 21, 2005 4:51 PM PDT
One more reason to switch to OPERA.
Reply to this comment
At least you didn't say switch to FireFox
by July 21, 2005 5:39 PM PDT
I'm so happy to hear that you didn't say switch to FF because it's been riddle with bugs and missteps lately. See Dog Days for FireFox http://news.com.com/Dog+days+for+Firefox/2009-1032_3-5798545.html?tag=nefd.lede

As for Opera, I love this browsers functionality, it's the best. But if it were popular enough to attract hackers I think it would fare far worse then FF and IE. And for that mater, if the browser market share were reversed with FireFox having 90% of the market it would have 10 times more bugs then IE because hackers(I'm sure they're pissed off Microsoft Devs) are barely creating exploits for it.
View reply
Already there
by July 21, 2005 7:45 PM PDT
Already using 8.0.1 & it's fine for most things. But some sites only work with IE, and they are sites that I HAVE to use - so I have to keep IE too.
Windowzers taken for a ride! AGAIN!
by July 21, 2005 9:57 PM PDT
You folks that continue to pay Bill for the trash heaps he spews
from REDmond make me laugh. What makes someone put up with
such c r a p? It can't be the user friendliness, security, ease of use,
stability or the total cost of ownership. So what is it?

I guess if everyone switched to OS X or Linux then we wouldn't
have trash like Windoze to make us look so good.
Reply to this comment
All of the above
by Andrew J Glina July 21, 2005 10:21 PM PDT
All those reasons you mentioned (user friendliness, security, ease of use, stability and the total cost of ownership) work for me. But don't worry; I am sure that you have conviced someone to try Linux with your comment. But not me because I already have this year and it still sux. Again.

Incidently, what do you mean by "continue to pay"? I paid for Win2K once five years ago and I still love it. Do you lease your software or is it so bad that you are itching for the latest upgrade that oozes out?

Buy a Dell dude and leave Windows on it too.
View reply
(8 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.65%) 0.19 29.41
Dow Jones Industrials (0.34%) 34.92 10,344.84
S&P 500 (0.38%) 4.14 1,095.63
NASDAQ (0.29%) 6.16 2,144.60
CNET TECH (0.29%) 4.55 1,574.88
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right