On GameSpot: $299 PS3 Slim and price cut announced!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Dec 22, 2003 5:54:00 PM

A Web site that published a third-party patch to fix a security hole in Microsoft's Internet Explorer has had to reissue the patch, after the original was found to be flawed.

Openwares.org published the second patch Saturday, after the first was found to contain a buffer overflow exploit. This exploit, which allowed an attacker to take control of the patched PC, might have been far more damaging than the flaw the patch aimed to fix.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


According to Openwares, only about 6,500 people downloaded the original patch. Security experts with whom ZDNet spoke last week warned people against installing it, saying that aside from trust issues, the patch author would not have had access to IE source code; the patch could interfere with future updates from Microsoft.

Representatives from Microsoft were not available for comment Monday.

The IE vulnerability, which was first reported in late November, allows a browser to display one URL in the address bar while the page that's being viewed is actually hosted elsewhere, making the user more susceptible to ruses like "phishing," in which spoof e-mails direct people to fake Web sites that seem to belong to legitimate companies. However, Openwares' first fix, which worked by filtering out any URLs containing suspicious characters, would work only with addresses that had less than 256 bytes. Larger addresses produced a buffer overflow.

Openwares' administrator said: "The new version has been rewritten and tested by dozens of users who helped out. If you're unsure, look at the new source code for yourself."

By early morning Monday, there had been 2,500 downloads of the new patch. However, this is a minute fraction of IE users, who make up more than 90 percent of the Internet population.

Microsoft has still not released a fix for the IE problem or given any indication as to when one might be available. In October, the Redmond, Wash., software maker adopted a policy of releasing only one patch each month, but it has already announced that it will be skipping its December release; IE is expected to remain vulnerable until at least mid-January.

Earlier in December, weeks after the IE flaw was discovered, Iain Mulholland, a security program manager at Microsoft, said the company was putting heavy emphasis on increasing the quality of its patches and that the approach has had an effect on the timing of releases. "It is not that we are not doing anything; it's just that we don't have a patch ready in the pipeline," he said.

Normally, spending one or two months developing a patch would go unnoticed, because security flaws are usually reported to Microsoft long before they are made public. In this case, however, the software giant did not get any advance notice.

"They put Microsoft's nose out of joint by publishing it, rather than telling Microsoft first and keeping quiet for the requisite six weeks," said Graham Titterington, a principal analyst at U.K. consulting company Ovum.

Munir Kotadia of ZDNet UK reported from London. CNET News.com's Robert Lemos contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 27 Talkback(s)
To Mozilla Fan
That's ACCEPT. Not EXCEPT. (Read the rest)
Posted by: dr.daystrom Posted on: 01/28/04 You are currently: a Guest | | Terms of Use
What a joke  chrichton99 | 12/22/03
The Joke is IE  michael-t | 12/22/03
A better solution  issthatso | 12/22/03
Doesn't remove IE  rpmyers1 | 12/22/03
how so  JWatson77 | 12/22/03
ms shills mad  JWatson77 | 12/22/03
ZDNET needs better security "experts"  rpmyers1 | 12/22/03
Sheep make anti-wolf patches for wolves. That's "smart". (NT)  Vily Clay | 12/22/03
Who in their right mind...  Damon K | 12/22/03
It is *NOT* a patch  rpmyers1 | 12/22/03
don't install it  JWatson77 | 12/22/03
Break how?  rpmyers1 | 12/22/03
My IE /is/ broken  Robert Carnegie | 12/23/03
Does it matter  JWatson77 | 12/23/03
you are an IT guy?  Valis Keogh | 12/29/03
I've used it, it works  ebudae@... | 12/23/03
Leo said don't use it, so I didn't  FilledOut | 12/23/03
OSS patches on proprietary software isn't a good idea  Michael Kelly | 12/23/03
proprietary software isn't a good idea  Immanuel Tranz-Mischen | 12/23/03
Hmmm.  chippsetter@... | 12/23/03
mmmH  Immanuel Tranz-Mischen | 12/23/03
But so many companies make proprietary software  FilledOut | 12/23/03
How wrong you are  nucrash | 12/23/03
Lest anyone assume...  Immanuel Tranz-Mischen | 12/23/03
Ultimate IE Fix  dwest_z | 12/23/03
yes but  JWatson77 | 12/23/03
To Mozilla Fan  dr.daystrom | 01/28/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More