Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Internet Explorer 6 - New "Object Tag" critical vulnerability

  A new Internet Explorer 6 vulnerability has been documented by Secunia and so far no exploits have surfaced.  Still folks should always be careful with sites they visit and avoid all URL links in spam email.

Internet Explorer 6 "object" Tag Memory Corruption Code Execution
http://secunia.com/advisories/19762/

QUOTE: The vulnerability is caused due to an error in the processing of certain sequences of nested "object" HTML tags. This can be exploited to corrupt memory by tricking a user into visiting a malicious web site.  Successful exploitation allows execution of arbitrary code.  The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.