News
[PSUs]| Wednesday 22nd March 2006 |
In a security notification, Michal Zalewski writes 'This might not come as a surprise, but there appears to be a *very* interesting and apparently very much exploitable overflow in Microsoft Internet Explorer'.
The vulnerability
ADVERTISEMENT |
|
Zalewski says the exploit works with a fully patched version of Internet Explorer 6 with Windows XP Service Pack 2. Other browsers such as Firefox and Opera are not susceptible to the flaw. Nevertheless, Secunia has marked the exploit as 'non-critical'.
Microsoft says it is aware of the problem and is looking into it. However, given the 'non-critical' nature of the vulnerability, the earliest a fix is likely to appear is on the next 'patch Tuesday' in April.
Anyone who feels like experiencing the exploit themselves Zalewski offers a site where visitors can crash their browser.
Submit to: Digg | Slashdot | Del.icio.us | Technorati







