IE 7 beta open to parser attack

Hi forum folks,

The new IE 7 beta has a vulnerability in the new version of urlmon.dll and could open possibilities for a parser attack with a specially crafted version to cause a crash (denial of service)l; read here:
http://security-protocols.com/advisory/sp-x23-advisory.txt

I wonder if it is the same old exploit back from 2003 that plays up again three years later: see for details here:
http://www.securiteam.com/windowsntfocus/5NP050UAKY.html
If that is so it means these coders do not learn from past mistakes.

polonus


Well, that is not good. :frowning:


Well Polonus, it doesn’t look good having this vulnerability. But, it’s still in Beta so hopefully this will be taken care of. :-\


Yep … the reason for it being released in beta! :slight_smile: