Fasten your seatbelts – Browser vulnerability a day to be announced in July



I hope there aren’t too many browser developers that have planned on taking July off….. I ran across browserfun.blogspot.com where it is planned to release information on a web browser vulnerability EACH DAY for the month of July. This comes to us from HD Moore of Metasploit. Judging from This securityfocus article, most of the vulnerabilities may just lead to a browser crash, but some seem to be remote code execution vulnerabilities. Microsoft Internet Explorer is where they found most of them, but other browsers were NOT immune and did find at least one remotely exploitable vulnerability to gain remote access for each browser tested.


Basically, from security focus…. they’ve used fuzzing tools to test browsers. In the past, fuzzing has been used to test network devices and the attention has been more on servers rather than client application. They’ve found over 50 flaws in Internet Explorer. More background on HD Moore’s details on browser fuzzing can be found here. One of the first two already looks fairly serious…. FRSIRT analysis.

BTW on July 11th Microsoft will no longer provide updates for Windows 98/98SE and ME…. I hope the August updates will address some of these issues (I doubt they’ll have patches in by the July patch day.) Of course, keep in mind it’s NOT JUST Internet Explorer that they’ve found vulnerabilities with. (Although it sounds as though most of them are IE vulnerabilities.)

Related Posts

Blog Traffic Exchange Related Posts
  • Update on the Internet Explorer VML vulnerability Just catching up on the days VML vulnerability news from today.... It looks as though... the exploit is now MUCH more widespread this blog has some video of an infection, what's notable is that the first take was VERY UNEVENTFUL, it was used to stealthily install a keylogger. (So that......
  • Internet Explorer zero-day This time around, the zero day is related to Internet Explorer and activex... (directanimation specifically). Incidents has a good update on the issue. This is a second exploit, there was another at the end of August, MS has an advisory on the issue. I think a safe bet would be......
  • Other MS patch news as well as a Yahoo vulnerability? Or lack of currently available patch as the case may be. From the previous link it appears that there was at least one previously announced vulnerability that was not addressed in the recent patch day from Microsoft. From MS... "this is a DoS only issue that was not addressed in......
Blog Traffic Exchange Related Websites
  • Why Use Internet Monitoring Software Internet monitoring has become a necessary step if you're having the internet connection. There is internet monitoring software to monitor your children who are using the internet or to have a close look on your employees. There are many things that can be monitored and its results can be delivered......
  • New Version of Google Toolbar for Firefox When Firefox 3 was officially released, the Google Toolbar was not supported.  Of course, that didn't stop me from manually updating the MaxVerison myself so that it would work.  Although it didn't take long for Google to release a new version that officially supported Firefox 3, I was disappointed as......
  • What to Look for in Your Blogging Software There are so many choices for blogging software on the market, that it can be very difficult to choose the right one. Every software choice has its advantages and disadvantages which means that you will have to make some decisions on your needs. This will help you to determine which......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site