OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: IE 4.01 bugs in Win95 & WinNT. (long)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IE 4.01 bugs in Win95 & WinNT. (long)


  • To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
  • Subject: Re: IE 4.01 bugs in Win95 & WinNT. (long)
  • From: David LeBlanc <dleblancISS.NET>
  • Date: Mon, 16 Mar 1998 13:25:46 -0500
  • Comments: To: "Abe L. Getchell" <agetchelKDE.STATE.KY.US>
  • In-Reply-To: <199803161557.KAA19688loki.iss.net>
  • Reply-To: David LeBlanc <dleblancISS.NET>
  • Sender: Windows NT BugTraq Mailing List <NTBUGTRAQLISTSERV.NTBUGTRAQ.COM>

At 10:15 3/16/98 -0500, Abe L. Getchell wrote:

>        Microsoft's position in this matter is, "The IE team has put this
bug in
>the bug database, and it will be fixed in the next release or service
>release."  Personally, I think that bugs like these in commercial
>software are unacceptable, but I can understand why they took the
>position they did.  As Russ said in an e-mail to me, "...and while GP'ing
>your machine is not a good thing, you're not likely to return to the site
>that caused it...".  Make of it what you will...  If you have any
>questions, feel free to contact me at agetchelkde.state.ky.us.  Thanks
>for listening...

Unless someone can come up with some way to use these bugs to cause a stack
overwrite, then I'd have to agree that MS is doing the right thing.  Since
it doesn't appear to really be a security breach, and isn't something we're
actually going to hit very often in the wild (i.e., a correctly created web
page won't zap you), this constitutes a medium priority bug (IMHO), which
should get fixed in the next rev, but isn't worth incurring the
considerable expense of QAing a full dot release.


-----------------------------------------------------------
David LeBlanc                   | Voice: (770)395-0150 x138
Internet Security Systems, Inc. | Fax:   (770)395-1972
41 Perimeter Center East        | E-Mail:  dleblanciss.net
Suite 660                       | www: http://www.iss.net/
Atlanta, GA 30328               |