March 20, 2006 2:28 PM PST

New bug can crash Internet Explorer

Microsoft is investigating a newly reported flaw in Internet Explorer 6 that could cause the browser to crash when viewing a malicious Web page, the company said Monday.

Details of the security weakness in the Web browser were published on a popular security mailing list last week by researcher Michal Zalewski. "This might not come as a surprise, but there appears to be a very interesting and apparently very much exploitable overflow in Microsoft Internet Explorer," he wrote.

The flaw can be exploited by an attacker to crash IE, Secunia said in an advisory published Monday. The vulnerability has been confirmed on a fully patched PC running IE 6 and Windows XP with Service Pack 2, the security monitoring company said. Secunia deems the issue "not critical."

Microsoft is investigating the issue, a company representative said in an e-mailed statement. "At this time, we are not aware of any attacks attempting to use the reported vulnerability," the representative wrote.

Once it completes its inquiry, Microsoft said, it may issue a security advisory or provide a patch through its monthly release process.

See more CNET content tagged:
Microsoft Internet Explorer 6, Microsoft Internet Explorer, flaw, security, Microsoft Corp.

Add a Comment (Log in or register) 72 comments (Showing first 20 comments)
I know for a fact..
by OneWithTech March 20, 2006 3:05 PM PST
I've watched it happen in front of me while doing research on
spyware. All of a sudden -- the hard drive goes nuts and CRASH IE
is taken out.

Wake up and by a Mac!

~Justin
Reply to this comment View all 5 replies
Live.com
by advs89 March 20, 2006 3:44 PM PST
Microsoft's live.com has crashed my browser many times...
Reply to this comment View all 3 replies
IE
by Lee in California March 20, 2006 4:08 PM PST
Do people really still use Internet Explorer???(unless they are at work and have no choice)

Thats weird.
Reply to this comment View all 3 replies
indeed it crashes
by julianrodriguez March 20, 2006 6:28 PM PST
hehehe.... yes... it crashes
Reply to this comment View reply
Simple, Use Firefox or Opera
by wakizaki March 20, 2006 8:58 PM PST
Why does everybody still entrenched in using Internet Exploder :P Install Mozilla Firefox
or Opera and say goodbye to IE :D
Reply to this comment
There's really no excuse for this in 2006
by Jackson Cracker March 21, 2006 12:27 AM PST
Buffer overflow is something that has been well known and well understood for decades now.
Microsoft needs to do an investigation to find the programmer(s) responsible,
and work together with other software companies to develop a blacklist so that
incompetents don't just move on to another unsuspecting employer.
Reply to this comment View reply
What bunk...
by Walt Connery March 21, 2006 4:02 AM PST
When will people wake up and smell the coffee, and stop being such easy dupes? The purpose of this so-called "security advisory" doesn't either enlighten or help a single, solitary soul--except maybe hackers who find their "jobs" (heh...;)) made easier by the process of self-styled "security firms" publishing details surrounding the holes they find.

The obvious answer to why a "security firm" would publish such information, information it deems "non-critical" and information surrounding a hole that has never been exploited by any entity except the "security firm" itself, is that the publication of such information is positive PR for the security firm itself. Outside of self-promotion for the "security firm," this information has no *positive* value whatsoever.

This is akin to Symantec publishing details of a virus that no one has ever contracted, and that no one has ever written before, in the hopes that someone will take this information and write a virus with it so that Symantec could then provide a "cure."

This "security firm" nonsense is a racket, pure and simple. A pity that so few people can see past the length of their own shallow prejudices to see it.
Reply to this comment
Been there...
by March 21, 2006 4:42 AM PST
...done that. Why am I not surprised by this? I guess it's because we always end up reading stuff about IE's vulnerabilities. Old news!
Reply to this comment
I appreciate Microsoft's consideration.....
by Earl Benser March 21, 2006 5:35 AM PST
.... by NOT developing any more IE versions from the Mac. To show
my appreciation, I have removed all copies of IE from my PC's too,
as much as IE can be removed from Windows. MS really welded IE
into Windows to beat out Netscape.
Reply to this comment View reply
MS should stick to games only before they kill someone...wait, they did!
by booboo1243 March 21, 2006 5:53 AM PST
MS should stick to games only before they kill someone as a direct result of poor quality products. Wait a minute, they did already. If you take the one death directly attributed to the blackout of '03, which I believe was caused by major power lines failing. The people tasked to monitoring those failing lines did not know there were issues developing, because the systems used were down due to a Microsoft virus. If it wasn't for the Blaster worm the blackout that cost millions of dollars ...maybe a billion? ...probably never would have happened.
Reply to this comment View all 4 replies
Facts? Here are some facts...
by booboo1243 March 21, 2006 7:31 AM PST
The *nix systems are being phased out for SCATA based systems, which all too often are being controlled by Windows virus based systems.

There were key PCs tasked to monitoring only, that were infected with viruses while the "host of other issues" were playing out. Trees take down power lines all the time, are you telling me the blackout of '03 was the only instance where trees took down lines? It was because of Microsoft infected devices tasked to monitoring this event failing, that action was not taken in a timely matter that may have prevented the blackout. That's where those of us not being paid off point fingers, with untainted common sense.
Reply to this comment View all 3 replies
This bug
by Charleston Charge March 21, 2006 8:15 AM PST
is not out in the wild AND it requires user interaction. It seems to me that if this same story was for the Mac everyone would be crying out FUD. I'm a Firefox and Opera user myself but it's just kind of amusing how one sided some of these posts tend to be.
Reply to this comment
Just DO IT and stop griping about it
by Seaspray0 March 21, 2006 8:48 AM PST
If you don't like it, then wipe all microsoft software from your computer and install something else. There are alternatives avaialable and you do have a choice. If you are using somethine else, then you have no reason to vent your stupid complaining because you are not affected.

So why is it that almost all the complaining is from people who don't even use microsoft software? Oh, come on... you're so easy to spot... "M$, Micro$oft, Windoze, Just another example, etc, etc, etc." You have no right to complain; YOU DON'T EVEN USE IT.

I've had about enough from you MAC boys and Linux groupies. I'm not talking about everyone who uses Linux or MAC. Nope, just those of you who have nothing better to do with your pathetic, useless life than constantly complain about an OS you don't even use. Don't like my post? Byte me!
Reply to this comment View reply
How Long Will it Take To Fix?
by March 21, 2006 11:32 AM PST
Isn't the real question how long will it take for Microsoft to fix this vulnerability? Even tho this is not out in the wild they should be proactive and fix it!
Reply to this comment
Exactly which part
by sylhyntm March 21, 2006 1:50 PM PST
of the english language do you not understand?

I kinda thought I made it pretty clear that I was nearly exhausted and got ahead of myself - forgetting to go back and re-read before posting. Had I, I would have corrected that first part to read so that it was clear that the Tabbrowsing did exist on IE (NOW, like after it had long been a feature in Mozilla projects - same as RSS feeds and anti-pop-up and phishing features) Features that mysteriously didn't appear in IE until they began to see some market erosion.

So - can you write a add-on to IE that enables even more flexibility to the Tabs? Probably not.
Can you write a feature to add enormous functionality in other parts of IE - no - you probably cannot.

By the way - can you remember the original instruction set for the 4086 processor - you know - the one that preceded the 8086 that was originally used in the first IBM PC's?

Yeah, I probably have forgotten more advanced programming techniques from the previous generations than you have mastered in the current.

Do you also have any in depth analog computing experience behind you? How about computers that don't even use electricity (like the pnuematic/hydraulic forced balance analogs I was responsible for on the USS Ranger)?

30 years and then some - but ONLY 30 as a recognized professional. The earlier work only got me statewide recognition in Ohio - and numerous scholarship offers while I was still in high school. Doing stuff like operational amplifier research and early gated logic circuits.
Reply to this comment View reply
THIS is NEWS?
by dlmeyer March 21, 2006 10:14 PM PST
I'm a Mac guy. I'm a Mac guy in part because I'd rather not deal
with Microsoft's standard of 'excellence' unless I'm paid for the
effort. I firmly believe things about Microsoft that could get me
sued for slander or libel or some such.

Know where I'm coming from? OK. I'm telling you that this is not
a big deal. the bug allows a remote site to crash your browser.
While that is more of a disaster than has been successfully
visited on many Mac users, this is worth an uproar because ...? It
could annoy you by closing your other tabs ... oh, does IE have
those yet? It's no big deal! You restart IE and don't return to that
site ... and just what will you tell your wife or boss you were
doing there anyway?

Please ... even an enemy of the Evil Empire can't get roused over
this one.
Reply to this comment View reply
 See all 72 Comments >>
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    At 10 years old, whither Google?

    Daniel Sieberg of CBS News looks at how the company grew exponentially from start-up to superstar and part of our culture, but what's ahead?

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    Mozilla releases second Firefox 3.1 alpha

    Added features include support for a new video tag element introduced with the HTML 5 standard, along with some speed enhancements.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.