Newsletter:

Skip Navigation LinksHome > News > Security > Watchdogs warn of IE 6 flaw

Watchdogs warn of IE 6 flaw

By Shaun Nichols
27 June 2008 01:34PM
Tags: watchdogs | warn | ie | flaw

Security experts are warning of a new security vulnerability in Internet Explorer 6..

According to the US Computer Emergency Response Team (US-CERT), the vulnerability lies in the way IE 6 handles attempted cross-site scripting attacks. When code is embedded within a specially crafted HTML document, the security protections will not function properly, and the user is open to attack.

If successfully executed, US-Cert believes that an attacker could execute a cross-domain scripting attack in which the attacker could steal such things as cookies and security credentials without any warning to the user.

According to McAfee researcher Yichong Lin, the vulnerability was first disclosed in a Chinese security publication known as 'pstzine.' Lin noted that a similar concept, known as "Ghost Pages" has previously been discussed by researchers.

While there is no fix for the vulnerability currently available, both Firefox and Internet Explorer 7 are protected from the attack. Both McAfee and US-Cert recommend that IE 6 users upgrade to the latest version of the browser to avoid infection.

Users who do not wish to upgrade are advised by both companies to disable scripting.

Copyright © 2008 vnunet.com

   


Ads by Google



Product Reviews

Star Rating
NetIQ's Secure Configuration Manager (SCM) is a combination of client server and web-based components to help...
Star Rating
Secure Bytes Secure Auditor is actually a suite comprised of several different pieces designed to audit...
Star Rating
For this review, I decided to combine these products into a single group of their own. Please keep in mind...
Star Rating
The netVigilance SecureScout EagleBox SP 2.0 is a highly comprehensive vulnerability management product.
Star Rating
The StillSecure VAM appliance is serious vulnerability management in a single device.


TopTopics
(4914) -  microsoft
(3239) -  google
(2357) -  telstra
(2354) -  internet
(2353) -  ibm
(2224) -  intel
(1803) -  network
(1694) -  iphone
(1635) -  broadband
(1491) -  australia
(1120) -  nbn
(1117) -  business
(1084) -  digital
(1014) -  windows
(978) -  security