On MovieTome: First Look: Jessica Alba in 'Machete'!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Mar 28, 2006 9:29:00 PM

Another company has released a third-party patch for a serious flaw in Internet Explorer, as experts warn users to be cautious with non-Microsoft fixes.

Determina, which makes intrusion-prevention products, made an unofficial fix for the Microsoft Web browser available on Monday. The release came shortly after eEye Digital Security issued its own temporary patch.

Both fixes are meant to protect Windows PCs against cyberattacks that exploit a recently disclosed IE vulnerability Microsoft has yet to provide an update for. The software maker has not endorsed either fix, saying that as a rule it doesn't recommend installing outside patches.

This is the second time this year that somebody has beaten Microsoft to the punch with a security fix. Last time, security experts supported a patch issued by a European researcher. This time, they are not recommending people apply the unofficial fixes.

Instead, people should follow Microsoft's advice and disable the Active Scripting feature in IE, or simply use a different Web browser, experts said.

"At this point, we do not recommend applying these temporary patches," said Johannes Ullrich, the chief research officer at the SANS Institute. Only those people who need to use Active Scripting in IE should consider adopting an unofficial solution, he said.

The vulnerability has to do with how Internet Explorer handles the "createTextRange()" tag in Web pages. Since the flaw was disclosed publicly last week, more than 200 Web sites have been found to exploit it. These sites typically install spyware, remote control software and Trojan horses on vulnerable PCs, according to security company Websense.

Andreas Marx, an antivirus software specialist at the University of Magdeburg in Germany, said the security issue with IE is significant, but agreed that a third-party fix is not needed. "I would not apply this patch personally," he said. "As long as you're not using IE, you're safe. If you do use it, you should deactivate Active Scripting."

Active Scripting, also known as ActiveX Scripting, is used to deliver "feature-rich" Web sites that can run small applications. Disabling the component in IE can have an impact on how well Web sites function in the browser.

Heeding the expert advice, Susan Bradley, a network administrator at an accountancy firm in Fresno, Calif., said she is not deploying any unofficial patch. "When any of these third-party patches are considered, one needs to think about supportability. It potentially puts me outside of support," she said.

The eEye and Determina patches block access to the vulnerable component in IE 5 and 6, the most used versions, to try to prevent malicious Web sites from taking advantage of the flaw. Both Determina, based in Redwood City, Calif., and eEye, of Aliso Viejo, Calif., sell intrusion-prevention products.

Microsoft has said it is working on a fix for the browser. That update is currently slated for delivery on April 11, Microsoft's regular monthly patch day. However, the Redmond, Wash., company has said it is considering an earlier release.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 33 Talkback(s)
Or else what?
Everything has holes even the sacred BSD. Which is my 'nix OS of choice btw.

Here are the latest holes from securityspace.com. Notice the BSD items.


The following vulnerability test(... (Read the rest)
Posted by: Code Poet Posted on: 03/31/06 You are currently: a Guest | | Terms of Use
But MS is quick to install their own spyware  grfdsgfsd | 03/28/06
So much for the MS monopoly  tic swayback | 03/28/06
Third-party patches are not thoroughly tested!  cnfrisch | 03/28/06
Ok  zkiwi | 03/29/06
TWO unofficial patches now!  Tony Agudo | 03/28/06
It's called FIREFOX!  An_Axe_to_Grind | 03/28/06
Let's do a little rewrite here  rick752 | 03/28/06
BAD RESULTS  RON FROM LA | 03/28/06
Well, it is a "last resort"  Tony Agudo | 03/28/06
Second unofficial fix plugs IE hole  Loverock Davidson | 03/28/06
Patch will be too little, too late  Mr. Roboto | 03/28/06
not for me  Loverock Davidson | 03/29/06
Well  zkiwi | 03/29/06
I do (NT)  Loverock Davidson | 03/29/06
Not exactly the advice recommended...  jasonp@... | 03/29/06
LOL You really crack me up  Loverock Davidson | 03/29/06
Amazing...  jasonp@... | 03/29/06
Wah wah wah  Loverock Davidson | 03/29/06
It's called BSD  Boot_Agnostic | 03/29/06
Or else what?  Code Poet | 03/31/06
MS Deliberately Dragging It's Feet on Fixes  wwwsupport | 03/29/06
Are you serious?  shraven | 03/29/06
I think you are right  patrick@... | 03/29/06
40 Mhz AMD Faster - It's all down to code !  wwwsupport | 03/30/06
oh sure just disable active scripting  rogerpay | 03/29/06
reality check...  JonnyZ | 03/29/06
Disabling Active X scripting....  DragonBRockin | 03/29/06
Hell you DON'T need ActiveX Scripting enabled just to read posts  patrick@... | 03/29/06
people use IE to do more than read posts  corticus | 03/29/06
You ARE dying in the water  patrick@... | 03/29/06
Take Firefox and...well no thank you.  DragonBRockin | 03/29/06
Another security flaw in IE? Yawn! Why do people still use it?  patrick@... | 03/29/06
Disabling active scripting  mdh75ab@... | 03/29/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More