Skip to main content

An IE bug rises again after two years

posted onOctober 25, 2004
by hitbsecnews

According to security researchers, recent updates to IE contain a serious fallback that
leaves systems once more vulnerable to a flaw that was fixed more than two years ago. This vulnerability, which involves how IE processes XML files, gives rise to information disclosure risks. The security bug was patched and closed back in Aug 2002, six months after Microsoft was initially notified about it by an Israeli firm. Microsoft rated the vulnerability as "moderate" when it fixed the flaw as part a cumulative update (MS02-047) to IE issued on August 22 2002.

That should have been the end of it but the bug resurfaced again late last week, when veteran browser bug hunter Georgi Guninski retested the issue and found the patch is no longer applicable. Now IE is vulnerable despite a cumulative fix issued earlier this week along with nine other security updates in the latest monthly patch batch from Microsoft.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th