Fasten your seatbelts – Browser vulnerability a day to be announced in July



I hope there aren’t too many browser developers that have planned on taking July off….. I ran across browserfun.blogspot.com where it is planned to release information on a web browser vulnerability EACH DAY for the month of July. This comes to us from HD Moore of Metasploit. Judging from This securityfocus article, most of the vulnerabilities may just lead to a browser crash, but some seem to be remote code execution vulnerabilities. Microsoft Internet Explorer is where they found most of them, but other browsers were NOT immune and did find at least one remotely exploitable vulnerability to gain remote access for each browser tested.


Basically, from security focus…. they’ve used fuzzing tools to test browsers. In the past, fuzzing has been used to test network devices and the attention has been more on servers rather than client application. They’ve found over 50 flaws in Internet Explorer. More background on HD Moore’s details on browser fuzzing can be found here. One of the first two already looks fairly serious…. FRSIRT analysis.

BTW on July 11th Microsoft will no longer provide updates for Windows 98/98SE and ME…. I hope the August updates will address some of these issues (I doubt they’ll have patches in by the July patch day.) Of course, keep in mind it’s NOT JUST Internet Explorer that they’ve found vulnerabilities with. (Although it sounds as though most of them are IE vulnerabilities.)

Related Posts

Blog Traffic Exchange Related Posts
  • 7 Updates coming from Microsoft in July We can expect 7 updates next week from Microsoft on the monthly patch day for July. Four of the updates will be for Windows, and 3 for Microsoft Office. There will be at least one critical update for each. It's expected that we'll see an update for the Excel issues......
  • Two new Windows exploits in the Wild | Wordpad Text Converter | Internet Explorer 7 XML Parser In the wake of a huge patch Tuesday, Microsoft has two new fires to be fighting. There are apparently "limited and targeted" attacks against a flaw with the Text converter component of Wordpad. Affected systems include Windows 2000 SP4, XP up to SP2, Server 2003 SP1 and 2. Vista is......
  • Internet Explorer 0-day (take 2 of the last few days...) The last zero day (activeX) seems to be less interesting than this NEW zero-day that really made a news splash in the last day. It looks as though this NEW 0-day affects VML... Incidents.org has good coverage here. Microsoft has an advisory up and they expect to release a patch......
Blog Traffic Exchange Related Websites
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site