Version: 2008
  • On TV.com: TOP 10 Shows CANCELED Too Soon

November 12, 1997 10:40 AM PST

IE 4 has hyperlink bug

  • Post a comment
Related Stories

IE hole exposes local files

October 17, 1997

Presario, IE 4 not compatible

October 14, 1997

Bug can crash IE 3, IE 4 beta

September 11, 1997

IE 4 beta bug risks hard disks

September 5, 1997

IE 4.0 beta is risky business

July 22, 1997

MS fixes latest IE bug

May 9, 1997
Microsoft (MSFT) last night posted a fix to an Internet Explorer 4.0 bug that could turn a hyperlink into a hornet's nest.

The company yesterday confirmed the existence of what it is calling the buffer-overrun security bug. The bug allows a malicious Web site author to take advantage of IE 4.0's limited capacity for Web addresses of the "res://" type.

Here's how it works: IE 4.0 can only read a res:// hyperlink address of up to 256 characters. Anything longer than that crashes the browser and causes the remaining characters of the address to go into the computer's memory. A malicious Web site author can make trouble simply by writing hostile code from the 257th character of the res:// address.

News of the bug was posted Monday to the advisory page of LOpht Heavy Industries.

"This is a very obscure bug," IE 4.0 group product manager David Fester said. "So far, no site has reported any damage, and no user has reported any damage."

Only people using Windows 95 and IE 4.0 are at risk, according to Fester. The fix is posted to the Microsoft IE security page.

advertisement

Latest tech news headlines

advertisement

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.22%) 22.75 10,388.90
S&P 500 (0.55%) 6.06 1,105.98
NASDAQ (0.98%) 21.21 2,194.35
CNET TECH (0.29%) 4.71 1,602.07
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right