All the latest UK technology news, reviews and analysis

Experts warn of yet another IE flaw

by James Middleton

26 Feb 2002

Be the first to comment

  • Tweet this

The Computer Emergency Response Team (Cert) today released an advisory warning of yet another vulnerability affecting Microsoft Internet Explorer and Outlook.

A buffer overflow vulnerability in the way Explorer handles embedded objects in HTML documents could allow an attacker to execute arbitrary code on a victim's system.

Explorer supports the '<embed>' tags which can be used to include arbitrary objects such as multimedia files, Java applets and ActiveX controls in an HTML document.

The 'src' attribute is used to specify the location of a file, but Cert warned that research by Russian researchers Security.nnov had found that Explorer does not properly handle the attribute.

This means that a maliciously crafted 'src' attribute in a web page or HTML email could trigger a buffer overflow, executing code with the privileges of the user viewing the document.

Microsoft has released a patch, and further information on this problem is available here.

The Cert advisory is available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

testjobpleaseignore (autoupload)

1329899014.71117-2574 testjobpleaseignore (autoupload...

Embedded C, Linux, RTOS, Agile, - Software Engineer - Staines

Embedded C, Linux , RTOS, Agile, MISRA – Embedded...

Software Engineer / Web Developer – Java, JavaScript, SQL

Software Engineer / Web Developer - Java, JavaScript...

C#, Oracle, Winforms, Junior Software Engineer, Central London 25-35k

C# , Oracle , Winforms, Junior Software Engineer – Central...

To send to more than one email address, simply separate each address with a comma.