All the latest UK technology news, reviews and analysis

Microsoft warns of 'critical' IE bug

by James Middleton

15 Jan 2002

Be the first to comment

  • Tweet this

Details of a vulnerability in Microsoft's Internet Explorer (IE) browser were released today after a 30-day 'cooling off' period to allow users to install the patch.

Depending on who you talk to, the bug reported on security mailing lists on 14 December is either the biggest hole ever to be found in IE or just an everyday glitch.

But the crux of the vulnerability is that by simply placing the characters %00, otherwise known as a null byte, into a filename on a maliciously configured web server, a user could be tricked into opening dangerous content.

Online Solutions, the security firm credited with discovering the flaw, explained that a filename such as 'README.TXT%00PROG.EXE' would appear to open Readme.txt but, in reality, could open the potentially malicious Prog.exe.

Combine this with another issue in the content disposition header and Mime type, and the browser could be tricked into downloading and running a program without any download dialogs or warnings at all.

Microsoft has acknowledged that IE versions 5.5 and 6 are vulnerable and has given the flaw a 'critical' rating.

Microsoft's advisory can be seen here and Online Solutions has set up a vulnerability test here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

11%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Sales and Service Administrator

Our client, a specialist in their industry, is working...

Project Manager

JOB DESCRIPTION Job Title: Project Manager...

Java Entwickler

Für unseren Kunden, ein spannendes IT Unternehmen in...

Application Support Analyst with Oil & Gas Trading & Operations

Application Support Analyst with Oil & Gas Trading...

To send to more than one email address, simply separate each address with a comma.