User loginNavigationInternet Security News |
MS06-042 Related Internet Explorer 'Crash' is Exploitable - From eeye.comMS06-042 Related Internet Explorer 'Crash' is Exploitable Date: Severity: Systems Affected: Overview: Later on August 11th Microsoft created a knowledge base article which talked about problems with the MS06-042 patch and how Internet Explorer could crash when viewing some web pages that used compression. This Microsoft KB article referenced a patch, which could be requested through Microsoft Product Support Services, that would fix the "crashing" bug. There was further discussion about the extent of the crashes and widespread nature of the bug on places such as SANS and various patch and IT mailing lists. Because of the widespread discussions and number of people experiencing the Internet Explorer crash various security researchers, including eEye, decided to investigate as a lot of times crashes can be exploitable. We have since found that indeed the reason that people are experiencing Internet Explorer browser crashes is certain websites, that use HTTP 1.1 compression (as stated by Microsoft ), are causing a non-malicious buffer overflow to occur within Internet Explorer. After investigating and confirming that indeed this is an exploitable condition we are alerting people to the true severity of these "crashing" problems that people are experiencing, so that they can take the appropriate mitigation steps as need be. To Read the entire contents of this article, CLICK HERE to visit eeye.com
Submitted by cybernoggin on Wed, 08/23/2006 - 7:01am. categories [ CyberNoggin.com Security Blogs | Vulnerabilities ]
cybernoggin's blog | login or register to post comments
|
TRANSLATION - übersetzen, traducir, traduire, tradurrePoll |