Version: 2008
  • On CHOW: Groundbreaking hangover cure

March 17, 1998 12:35 PM PST

Bug can crash IE 4.01

  • Post a comment
Related Stories

Microsoft to update retail IE

March 2, 1998

Bug sends Navigators to IE

February 17, 1998

IE 4.0 gets an upgrade

December 2, 1997
A new bug that crashes Microsoft's Internet Explorer 4.01 browser is an annoyance but does not seem to pose a security threat.

Because of the flaw, a Web page designer can exploit the HTML "object" tag to make a user's browser crash and most likely force him to restart the system. The bug has been tested and found on IE 4.01 for Windows 95 and NT 4.0 systems.

Microsoft acknowledged the bug but stressed that a mischievous programmer must add a specific block of HTML to his Web site to affect users.

The worst-case risk apparently is loss of any unsaved data and settings when the browser crashes. Neither Microsoft nor Abe Getchell, a system administrator who posted news of the bug to the Bugtraq mailing list yesterday, have found more serious security implications. Microsoft isn't in a hurry to fix the problem.

"Microsoft has no current plans to implement a fix for these issues," a spokeswoman said. She added that Microsoft always works to improve the browser but declined to comment on release dates of future upgrades or "maintenance releases."

Bugs in Internet software draw great attention because of the possibility of network security breaches from the outside. Security flaws in both Microsoft and Netscape Communications' browsers have allowed, at least theoretically, the viewing or pilfering of users' local files. But few if any cases of actual mischief have ever been detected or reported.

"Personally, I think that bugs like these in commercial software are unacceptable, but I can understand why [Microsoft] took the position it did," Getchell wrote in his posting to Bugtraq. He was not immediately available for further comment.

The problem has three variations based on slight changes to the HTML, according to Getchell. All three variations cause the browser to get stuck in a loop and either crash or eat up system memory.

advertisement
Click Here

Latest tech news headlines

advertisement

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (2.03%) 203.52 10,226.94
S&P 500 (2.22%) 23.78 1,093.08
NASDAQ (1.97%) 41.62 2,154.06
CNET TECH (2.03%) 31.21 1,569.61
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right