Slashdot Mirror


Highly Critical Hole Found in IE

dotpavan writes "Eweek reports on a highly critical MS Internet Explorer hole found by Secunia Research's Andreas Sandblad. The vulnerability is due to the processing of the "createTextRange()" method call applied on a radio button control. From Secunia, "The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2." The vulnerability has also been confirmed in Internet Explorer 7 Beta 2 Preview (January edition) though it could be avoided by turning off Active Scripting, as suggested by Microsoft Security Response Center blog. How would this put MS in the market, hit by the ever-growing shots of vulnerabilties? And would the divorce of IE7 from Vista's Windows Explorer help?"

6 of 336 comments (clear)

  1. Patch available by thrillseeker · · Score: 5, Funny
  2. Highly Critical Hole Found in IE? by Anonymous Coward · · Score: 5, Funny

    Must be thursday.

  3. Perhaps it would save time... by Threni · · Score: 5, Funny

    ...if researchers just identified the bits that *weren't* totally insecure?

  4. It is not a dupe! by Life700MB · · Score: 5, Funny


    It's a brand new hole!


    --
    Superb hosting 20GB Storage, 1_TB_ bandwidth, ssh, $7.95

  5. Do what now? by Rob+T+Firefly · · Score: 5, Funny

    TFA: Microsoft plans to release a pre-patch advisory with workarounds for a "highly critical" vulnerability that could put millions of Internet Explorer users at the mercy of malicious hackers

    So this article updates us to the fact that they plan to update us with an article prior to the update?

  6. Proof of concept by Anonymous Coward · · Score: 5, Funny