« IE7 Has Trouble with Google Websites Windows XP Service Pack 3 Delayed Again »
First IE7 Vulnerability Discovered
Not even out 24 hours yet and a new vulnerability is discovered in IE7, it was discovered by Secunia and released today. It involves the handling of redirections for URLs with the “mhtml:” URI handler.
A vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to an error in the handling of redirections for URLs with the “mhtml:” URI handler. This can be exploited to access documents served from another web site.
Secunia has constructed a test, which is available at:
http://secunia.com/Internet_Explorer_Arbitrary_Content_Disclosure_Vulnerability_Test/Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected.
The solution they have listed is to disable active scripting support, and since there is now patch yet, if you use the test link they created above and find yourself vulnerable, you may want to consider disabling it until a patch is released.
Added: Saw this post on ha.ckers.org that says it allows anyone with control over a webserver to control anything you do with any page you can connect to.
This is some of the worst ownage I?ve seen in a long time. Secunia announced a really nasty cross domain leak for Internet Explorer. This allows anyone with control over a webserver to control anything you do with any page you can connect to. It?s interesting that Secunia marked it as a ?less critical? threat, as this pretty much gives any attacker read access to any domain anywhere as long as you are using Internet Explorer 6.0 or 7.0.
The only saving grace here is that it does require access to a server where you can write HTTP headers (or somewhere that you can do header injection/redirection) as you need to force the browser to go to a certain URL which then redirects to another URL.
So, they make it sound like it could be more critical than less critical, hehe. They say it will allow “complete ownage” of the internet for users of Internet Explorer. And three more weeks until the next patch Tuesday. Could be a long month.
Popular Tags
-
.net Framework
180solutions
AACS
access your computer
Access Your PC from Anywhere
Adware
Aero
Alex Eckelberry
Alienware
alienware computer deals
alienware coupons
AMD
antivirus
Antivirus XP 2008
AOL
Apple
Apple TV
Astronomy
Back to School
Backup
BackupHDDVD
Bill Gates
Blizzard
Blogging
Blu-ray
boot up
Botnets
Broadband
Browsers
Buy.com Computer Deals
CallManager
CES
Cisco
Cisco Call Manager
command line
computer bargains
computer coupons
computer deal
Computer Deals
Computer Forensics
Control Panel
Copy DVDs
Core 2 Duo
Dell
dell.com
Dell Computer Deals
Dell Computers
Dell Coupons
dell laptop deals
Dell XPS
Detailed Bookmarks
Digg
Domains
DoS
DoubleClick
Drivers
DRM
DVD
eBay
Education
Email
Engadget
Excel
FAT
File Recovery
Firefox
Gadgets
gaming computers
gaming laptops
Gaming News
Gateway
Gears of War
Gears of War Glitches
Gears of War Tips
Gears of War Videos
GeoRSS
Gizmodo
Gmail
Google
Google Checkout
Google Desktop
Google Docs
Google Earth
Google earth layers
Google Earth Videos
Google Maps
Google Pack
gotomypc.com
GPS
Halo 2
Halo 3
hard disk
Hardware
HD DVD
HDTV
hdtv-deals
How To
HP
HP Computer Deals
hp computers
HP Coupons
Hybrid Hard Drives
IBM
IBM AS/400 and iSeries
IE7
IE8
Instant Messaging
Intel
Internet Explorer
iPhone
iPod
iTunes
J&R Computer Deals
Joost
Julie Amero
KML
Lenovo
Lenovo Computer Deals
Linux
Live
Longhorn Server
Mac OS X
Malicious Websites
Malware
messenger
Microsoft
Microsoft News
Microsoft Office
Microsoft Security Bulletin
Microsoft Surface
MP3 player
MPAA
MSN Messenger
MySpace
MySQL
Networking
NTFS
Office 2007
Office Genuine Advantage
Office News
Office XP
OGA
online shopping
Opera
Overstock Computer Deals
Overstock Coupons
Panda
PatchGuard
pc access
pc remote access
phishing
Photoshop
Picasa
Picasa Web Albums
Piracy
PlaysForSure
PlayStation 3
porn
Privacy
Protect Children Online
PS3
RAM
RC1
Readyboost
reboots
registry
remote access
remote access software
Remote Assistance
remote connection
remote control computer
remote control pc
remote desktop
remote desktop administration
Remote Desktop Connection
Reviews
RIAA
Sandisk
Screensaver
Screen Savers
screensavers
Second Life
Security
service pack
Service Packs
Services
Shutdown Problems
Sidebar Gadgets
Silverlight
SiteAdvisor
Skins
Skype
Smartphones
Social Engineering
Social Networks
Software
Sony
Sony Computer Deals
Sony Coupons
SP1
SP2
Spam
spyware
Spyware Info
Startup Problems
Steve Jobs
Symantec
Tablet PC
Techmeme
Tech News
Televisions
Themes
This Site
thumb drive
TigerDirect
Tigerdirect.com
Tigerdirect Computer Deals
Tips
Toshiba
Toshiba Computer Deals
Toshiba Coupons
toshiba laptop reviews
Toshiba Satellite
Twitter
Ubuntu
UI
upgrade
USB
Verizon
Video Conferencing
Video Games
Video iPod
Videos
Virtualization
Virtual Machines
Virus Info
Vista Gadget
VML
vml-exploit
VoIP
vulnerability
Walmart Computer Deals
Wayne Porter
WGA
White Papers
Wi-Fi
WiFi
Wii
Windows
Windows 7
Windows 7 Videos
Windows 2000
Windows 2003
Windows Defender
Windows Explorer
Windows Genuine Advantage
Windows Home Server
Windows Live
Windows Live Drive
Windows Live Messenger
Windows Longhorn Server
Windows Media Player
Windows Messenger
Windows Mobile
Windows Readyboost
Windows Readydrive
Windows Server
Windows Server 2008
Windows Update
Windows Vista
Windows Vista Sidebar
Windows Vista Themes
Windows Vista Videos
Windows XP
Windows XP Themes
Windows XP Tips
Windows XP Tweaks
WinFX
Wireless
Wireless networking
WMF
Word
World of Warcraft
world of warcraft mods
WOW
WOW mods
www.gotomypc.com
X-Cleaner
Xbox
Xbox 360
Xbox Live
Xbox Live Marketplace
XPS
Yahoo!
YouTube
Zango
Zune
Zune Marketplace
Zune Phone
Zune Tips
2 Comments »
RSS feed for comments on this post.
| TrackBack URI
[...] By Jimmy Daniels Contributing Writer, RealTechNews [...]
Pingback by Alice Hill’s Real Tech News - Independent Tech» Blog Archive » First IE7 Vulnerability Discovered — October 19, 2006 @ 2:12 pm
[...] I posted earlier about the first IE7 vulnerability, found by Secunia, well, apparently, its actually a flaw in Outlook Express, from the Microsoft Security Response Center Blog, These reports are technically inaccurate: the issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express. [...]
Pingback by » First IE7 Flaw is Actually Outlook Express Flaw || Tech News and Tips from Tipsdr.com || — October 24, 2006 @ 3:13 am