Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » Security Watch » IE 7 bugs abound

Security Watch - IE 7 bugs abound posted in the Security & Safety forums; IE 7 bugs abound People didn't lose any time in finding bugs in the latest preview release of Internet Explorer 7. It's been but a day since Microsoft publicly released ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-03-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default IE 7 bugs abound

IE 7 bugs abound

People didn't lose any time in finding bugs in the latest preview release of Internet Explorer 7.



It's been but a day since Microsoft publicly released a test version of Internet Explorer 7, but Internet news groups and blogs are already teeming with bug reports. Also, one security researcher claims he found a security vulnerability in the new Web browser.

Issues reported several times include compatibility problems with McAfee security software and trouble installing the browser due to unnamed anti-spyware and antivirus tools. Some testers also said using certain features or surfing to specific Web sites caused the browser to hang or crash.

Microsoft made a preview version of IE 7 beta 2 publicly available on Tuesday, but the product is not fully baked, the company has said. The release is meant to give developers and IT professionals a chance to test-drive the software and give feedback to Microsoft so that the final version, expected later this year, and upcoming test releases, will have no, or at least fewer, issues.

The public preview release of IE 7 includes many of the features Microsoft has been touting for months. Among them are new security and privacy protection capabilities such as mechanisms designed to combat phishing attacks, spyware and other threats.

But browser testers may already be at risk, according to security researcher Tom Ferris. Late Tuesday, Ferris released details of a potential security flaw in IE 7. An attacker could exploit the flaw by crafting a special Web page that could be used to crash the browser or gain complete control of a vulnerable system, Ferris said in an advisory on his Web site.

Microsoft confirmed the security flaw and said it crashes IE, but is not exploitable by default to commandeer a PC, a company representative said on the IE team blog late Wednesday. The bug is scheduled to be fixed before the next public IE 7 release and was actually already found in Microsoft's own code review and analysis, the representative wrote. A Microsoft spokeswoman confirmed the authenticity of the blog post.

Also, the preview version of IE 7 clashes with some security software. Users reported that after they had downloaded and installed the beta, McAfee security software failed to display any text or graphics in their Windows when opened. Reinstalling the applications had no effect, according to the user reports.

"I have McAfee Internet Security Suite on my system, and when IE 7 is loaded, neither work," one tester wrote in Microsoft's news groups. "Surely...getting the system to work with an industry leader is a small price to pay."

Microsoft acknowledged the compatibility issues with the McAfee software in a response on the IE team blog. "The McAfee issue is known, and we'll work on this for a future build," a Microsoft representative wrote on the blog.
McAfee also said it is working to fix the problem with IE 7. "While the issue affects the way in which users view the McAfee interface, McAfee's automated protection is still running and protecting the user's systems," a company representative said in an e-mailed statement.

Other people had trouble installing IE 7 altogether, reporting an error during installation that stated a file called "msfeeds.dll" could not be found. This problem stems from compatibility issues with unnamed security applications, a Microsoft representative wrote in a blog post.

"Some anti-spyware and antivirus software is known to interfere with IE 7's ability to install," a Microsoft representative wrote. The software maker offers a work-around and otherwise recommends users wait until a future IE 7 release that it hopes will address the problem.


From:
http://news.zdnet.com/2100-1009_22-6034054.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #2  
Old 02-04-2006
double_a_ron's Avatar
Elite Member
My PC
 
Join Date: Sep 2005
Location: Canada
Posts: 901
PC Experience: Very Experienced
double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page double_a_ron - See this Members User comments on their Profile page
Default

Did they find a way to take control of the PC, I read that the bug was only useable to crash IE.


__________________
//Prework\\\///PCHF RULES\\\///Did we help? Please Donate\\\

CompTIA A+ Certified, MCDST



Did we help? Please hit that Thanks button.
  #3  
Old 02-04-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

More then just a crash it seems:

Code:
 
Overview: 
A denial of service vulnerability exists within Microsoft Internet
Explorer 7.0 Beta 2 which allows for an attacker to cause the browser to
crash, and or to execute arbitrary code on the targeted host.
 
Technical Details: 
When running a specially crafted .html file, urlmon.dll
inproperly parses the 'BGSOUND SRC=file://---' (approx. 344 dashes) and
causes the crash. 
 
The following html code will trigger the crash:
 
<BGSOUND
SRC=file://---------------------------------------------------------------------
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
---------------------------------- >
 
or hit the following url:
 
http://www.security-protocols.com/poc/sp-x23.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
<News> Two New Windows Metafile Bugs Found Newsie IT News 0 01-10-2006 07:30 AM

All times are GMT +1. The time now is 09:01 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top