Slashdot Log In
Unpatched IE Flaw Extremely Critical
Posted by
Zonk
on Tue Nov 29, 2005 12:52 PM
from the get-the-lead-out dept.
from the get-the-lead-out dept.
Durinthal writes "The biggest blip on the security radar over the Thanksgiving holiday was the realization by the security community that an Internet Explorer problem first identified six months ago was a lot worse than it appeared, as what appeared to be only a DoS vulnerability also allows for execution of arbitrary code. The realization caused Secunia to issue a rare 'Extremely Critical' advisory."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Extremely Dupical (Score:5, Funny)
Re:Extremely Dupical (Score:3, Informative)
All your OS are belong to Sun!
Scummy eweek popup alert (Score:5, Insightful)
Does anyone think that a very handy Firefox add-on would be a button attached to this kind of dialogue that would instantly kill all Javascript scripts stone dead for the page? Once an OK/Cancel dialogue is up, you can't interact with Firefox's UI until you've responded to the dialogue and let the Javascript do something, which I think is poor design.
Re:Scummy eweek popup alert (Score:5, Informative)
Parent
Re:Scummy eweek popup alert (Score:3, Informative)
Re:Scummy eweek popup alert (Score:3, Informative)
Unfortunately not. I can see that it would be useful to have, but a quick test shows that both Cancel and the Close button return false (on Windows 2000, IE 6 and Firefox 1.0.7). IIRC this is in line with the expected behaviour for such dialogs, although that may vary per operating system.
Try it: type
in your browser location bar
You mean to say I can be up to date (Score:2)
Re:You mean to say I can be up to date (Score:4, Insightful)
-Jesse
Parent
Reaction Time More Important (Score:3, Insightful)
Re:You mean to say I can be up to date (Score:4, Insightful)
Although it can be "accepted" that code be released with unknown bugs (because we all make mistakes), the problem here is that the bug report is over 5 months old. It is one thing to ship buggy code, it is another thing to ignore bug reports and not fix your product once the bugs have been found. It is no longer unknown, Secunia has a release date of 2005-05-31 for that bug.
Parent
is IE the sound that .... (Score:5, Funny)
"iiiieeeeEEEEEEEEE!"
Re:is IE the sound that .... (Score:4, Funny)
Parent
Re:is IE the sound that .... (Score:2, Funny)
No, real Geeks scream, "Kaaaaaaahn!"
Re:is IE the sound that .... (Score:5, Funny)
Parent
Wow (Score:2, Interesting)
Extremely Critical Firefox Vulnerability (Score:3, Insightful)
Firefox v1.5 (Score:5, Interesting)
Re:Firefox v1.5 (Score:4, Informative)
Hrm, did you notice that Firefox 1.5 is crashing as well on this exploit? It's not a security risk but a big annoyance nonetheless.
Parent
Proof of Concept (Score:5, Informative)
Re:Proof of Concept (Score:2)
-Jar.
Re:Proof of Concept (Score:5, Informative)
Parent
Re:Proof of Concept (Score:4, Funny)
Parent
Re:Proof of Concept (Score:3, Informative)
Re:Proof of Concept (Score:4, Informative)
So it disturbs the browser, but it doesn't hack it for me.
Parent
Re:Proof of Concept (Score:4, Interesting)
Yes, this is a very dangerous problem.
Parent
Re:Proof of Concept (Score:3, Informative)
Re:Proof of Concept (Score:3, Informative)
Re:Proof of Concept (Score:3, Informative)
Well, Opera just opened a small window which just sat there and did nothing. I closed it, and continued on my merry way. Score one for Opera.
Snow Crash (Score:4, Funny)
Parent
Patch here (Score:5, Funny)
Parent
Temp Fix (Score:5, Informative)
Control Panel -> System -> Advanced [Tab] -> Performance Settings -> Data Execution Protection [Tab] -> Turn on DEP for all programs and services except those I select -> Ok -> OK.
Re:Temp Fix (Score:4, Informative)
Parent
Re:Temp Fix (Score:3, Informative)
Perhaps hardware based DEP would make a difference, but again, for folks relying on software-based DEP, it's not effective - the exploit still works anyways.
Ron
It affects Firefox, too. (Score:5, Informative)
https://bugzilla.mozilla.org/show_bug.cgi?id=3173
ISC got counter of vulnerable systems (Score:5, Interesting)
McAfee Fails It (Score:5, Informative)
Am I the only one? (Score:4, Insightful)
Re:Am I the only one? (Score:3, Informative)
McAfee Catches it (Score:2, Informative)
Please stop accepting stories from Spammers (Score:3, Informative)
Just yesterday a famous spammer did the same thing and posted here. The slashdot editors should stop accepting such stories that are fabricated in order to boast his advertising revenue.
Simmer down (Score:4, Informative)
And here's the submitter's user page http://slashdot.org/~Durinthal [slashdot.org]
I think you mistook the submitter for **Beatles-Beatles
This Beatles guy is really getting out of hand.
He manages to taint stories he isn't even submitting.
Parent
AVG detects it (Score:3, Interesting)
Either way MS needs to get off their ass and fix the problem. Oh and as if everyone didn't already know, you should be using anything but IE for web surfing.
Excerpt from email my credit union sent (Score:5, Interesting)
"Currently, the only work-around is to temporarily discontinue the use of Microsoft Internet Explorer and use another browser, such as FireFox, (this can be downloaded for free at www.mozilla.com) until Microsoft can issue a patch."
Anyone else's bank send out a warning like this bluntly stating that if you use IE, there is nothing the bank can do to protect you?
Re:Excerpt from email my credit union sent (Score:5, Funny)
No, but I got an email from my bank stating that there is a problem with my account and they need my account info.
Parent
Worthless eWeek (Score:4, Interesting)
http://www.security.ithub.com [ithub.com]
The Proof of Concept [computerterrorism.com] didn't load calc.exe for me. Instead, it crashed my IE windows on WindowsXP SP1.
I run Ad Muncher [admuncher.com], so that might have caught and foiled the malicious javascript.
Parent
Re:Yawn... (Score:3, Insightful)
I don't agree at all. Let's look at the post that got downmodded:
Yawn... IE is vulnerable and this is news, why? Seriously, people, if you're using IE to actually surf the Web I would argue you're probably already vulnerable because your system is running Windows, all your settings are probably default, and you probably don't care.
The post adds nothing to the discussion, says this article isn't newsworthy and does a broad ad hominem attack on all users of IE. How is that not flamebait?
I probably wouldn
Re:Yawn... (Score:3, Interesting)
What I DO find interesting are moderation wars where a large number of points are expended upping and downing the same post. A few of my
Re:Don't fret! (Score:3, Funny)
Re:Firefox isn't perfect... (Score:3, Insightful)
Re:Firefox vulnerable too (Score:3, Informative)
The bugzilla title for this bug is 'hang when long wrappable string is passed to prompt()'.