New York Web Design News September 9 2003, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

IE Patch Doesn't Work
Web Design & Technology News, September 9, 2003

New Adobe Creative Suites
Google Ads Milestone
VeriSign Settles w/ FTC
OpenSSH Patches 2nd Flaw
Google's Local Search
Yahoo! Product-compare
VeriSign Defies ICANN
ICANN Responds to VeriSign
ISPs Limit Transfer Volume
Open-souce Security Flaws
VeriSign's SiteFinder Sued
DB2 Linux Security Flaw
MSFT Adopts Wi-Fi 802.11g

VeriSign's 404 Handling
Sun SW Intros@Confab
Symantec Security Servers
VCs Get More for Their $
Bright Outlook for HDDs
More Holes in MSFT Windows
New Macromedia Web Tools
IE Patch Doesn't Work
Scaled-down Intel Itanium-IIs
Lycos E-mail Troubles
IBM+Borland Challenge MSFT
Verizon Puts $1B into 3G
DOJ OKs Yahoo+Overture

More Web Design News:
2008 Current News
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



September 9, 2003

A patch released by MSFT to fix a critical security vulnerability in its Internet Explorer browser does not work, according to security experts.
By Patrick Gray

The "object type" vulnerability was discovered by eEye Digital Security around four months ago. A patch was released on August 20th. It was then re-released on August 28th, because under some circumstances it had caused problems for some non-default operating system installations, according to eEye. The patch appears to be due for yet another rerelease because it simply doesn't fix the vulnerability it is supposed to, eEye said.

The vulnerability in question can be exploited by crafting a malicious HTML file that, when viewed by an Internet Explorer browser, extracts and executes malicious code.

MSFT representatives were not immediately available for comment.

Marc Maiffret, eEye's chief hacking officer, said the vulnerability is particularly critical, because it doesn't take a lot of effort to take advantage of it.

"It's pretty serious just because it's so easy to exploit... it doesn't require someone to know how to write buffer overflow exploits or anything like that," he said.

Maiffret says MSFT should have done a better job to begin with. "How do you take four months to fix something this simple and then not fix it correctly?" he asked. "It seems like they are taking security seriously... (but) at the same time, I don't think they're really investing."

The lack of suitably skilled security engineers within MSFT is one reason, Maiffret said, this incident--described by the researcher who discovered the flaw in the patch as a "pathetic oversight" -- has occurred.

"A lot of it comes from having the right people in-house," Maiffret said. "They have some very smart guys in there, but they definitely don't have enough."

The problem with the security fix was first made public by security news and discussion site Malware.com, and Maiffret was unsure whether MSFT was informed prior to that disclosure. "They discovered it and they're getting the information out there... I'm not sure if they gave MSFT the information, which is usually the best way," he said.

Before the release of the patch, Maiffret's team looked over the patch and didn't see any problems. However, Maiffret said the examination was a quick "once over" and not a detailed audit. "(Our) researchers were just helping out; it's not like (MSFT) was paying us for this," he said.

MSFT uses external security code auditors, which in this case were not doing enough, Maiffret said.

Concerned users can disable active scripting on their browsers to mitigate the vulnerability until MSFT updates the patch.

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com