BetaONE will rise again!


Reply
  #1  
Old 21st Oct 04, 03:45 AM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
SECUNIA said there are two bugs in Microsoft Internet Explorer which can be exploited by wicked people and which bypass security features in Windows XP SP2.
The bugs were discovered by http-equiv, said Secunia, and compromise systems by insufficient validation of drag and drop events, and related to a security zone restriction error.

Secunia describes these bugs as "highly critical", and said they have been confirmed as existing in a system using IE 6 and Windows XP SP2.

The problems can be worked round by turning off Active Scripting, and that advisory is here.

Meanwhile, Secunia also said there are less critical bugs in Mozilla Firefox - the advice can be found here and relates to tabbed browsing capabilities. Similar problems have been found in Netscape 7.2, in Avant, and in Konqueror, as well as Opera, Maxthon and Safari.




Source:

The |NQ!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Update for Internet Explorer 6 for XP Service Pack 2 NewsBot BetaONE News 0 3rd Nov 04 11:00 AM
IE URL Spoofing Bug; SP2 Users Not Affected NewsBot NeoWin News 0 30th Oct 04 11:00 PM
PC Makers Seize the Reins of XP SP2 Security NewsBot NeoWin News 0 21st Oct 04 10:00 PM
PC Makers Seize the Reins of XP SP2 Security NewsBot NeoWin News 0 21st Oct 04 11:57 AM


All times are GMT +1. The time now is 02:28 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.