Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Windows IE5 vulnerable to BMP image security flaw.
http://www.securitytracker.com/alerts/2004/Feb/1009067.html ^ | Feb 15 2004 | Security Tracker

Posted on 02/16/2004 9:56:47 AM PST by Bobalu

click here to read article


Navigation: use the links below to view more comments.
first 1-2021-34 next last
Oh great... now viruses and arbitrary code can be executed from within an image file.

Better get rid of IE5 if you use it.... get mozilla or Opera.

1 posted on 02/16/2004 9:56:48 AM PST by Bobalu
[ Post Reply | Private Reply | View Replies]

To: Bobalu
Mozilla 5 (Netscape 7.01) is my current browser. I only fire up IE4 to check HTML for cross-browser compatibility.
2 posted on 02/16/2004 10:00:01 AM PST by holymoly
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu
I guess folks can't upgrade to IE6. (/sarcasm).

FIRE!! FIRE!! RUN FOR THE HILLS!!! THE SKY IS FALLING!!!

3 posted on 02/16/2004 10:01:42 AM PST by TomServo ("What a day. I invented Gainesburgers and I didn't even mean to!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu
Better get rid of IE5 if you use it.... get mozilla or Opera.

While I like Opera, Windows Update will only work under IE. It's better to go ahead and install IE6 and not have to worry about security in obsolete versions.

4 posted on 02/16/2004 10:01:42 AM PST by Paleo Conservative (Do not remove this tag under penalty of law.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu
Wow. I wish I knew half as much as these programmers do. I did get a bit of a chuckle out of the comment "Gayer than AIDS." Not that AIDS is funny, it's not. Not at all. But for some reason the comment tickled my funny bone.
5 posted on 02/16/2004 10:01:57 AM PST by Cboldt
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu
I've used IE6 for years.
6 posted on 02/16/2004 10:02:30 AM PST by Bush Cheney
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush Cheney
The report indicates that IE 5 is affected but that IE 6 is not affected.

5 is pretty old. Been on 6 for years.

7 posted on 02/16/2004 10:05:00 AM PST by MrsEmmaPeel
[ Post Reply | Private Reply | To 6 | View Replies]

To: Paleo Conservative
While I like Opera, Windows Update will only work under IE.

Good point. So load IE6 for that, but run Mozilla Firebird ('Firefox', in its latest version) the rest of the time.

My difficulty with Opera is that their answer to the problem of features that don't work is to add more features that also don't work.

8 posted on 02/16/2004 10:11:28 AM PST by Grut
[ Post Reply | Private Reply | To 4 | View Replies]

To: Bobalu
I have heard that Netscape uses Mozilla. Is that correct?
9 posted on 02/16/2004 10:17:56 AM PST by hsmomx3 (Want higher taxes? Don't move to Arizona.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Grut
My difficulty with Opera is that their answer to the problem of features that don't work is to add more features that also don't work.

But it's great for cutting down the number of brower sessions on my desktop. I can read muliple threads on Free Republic with only one browser session, and it is easy to shutdown.

10 posted on 02/16/2004 10:18:18 AM PST by Paleo Conservative (Do not remove this tag under penalty of law.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Bobalu
Reposted here by me. I couldn't find this thread again, and thought it had been deleted due to the politically incorrect comments.

One additional observation: I suspect that the versions of Outlook Express and Outlook that "match" IE 5 are also vulnerable, which would mean that an HTML message with an embedded BMP image could exploit this problem.

11 posted on 02/16/2004 10:55:21 AM PST by justlurking
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu
It is becoming clear that whatever Exploder is, it is not a web browser. First, we have Microsoft telling us not to click links in the browser; instead, we're expected to type in the URL displayed on the status bar. Now we find that you can't even trust it to display pictures!

If you can't click on links and can't see pretty pictures, it's clearly not a web browser.

12 posted on 02/16/2004 11:22:52 AM PST by Vroomfondel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vroomfondel
It is becoming clear that whatever Exploder is, it is not a web browser.

What is it about this statement that you don't understand, Einstein:
13 posted on 02/16/2004 11:48:58 AM PST by Bush2000
[ Post Reply | Private Reply | To 12 | View Replies]

To: Bush2000
What is it about this statement that you don't understand, Einstein:

Don't you have anything better to do than harass anyone that happens to post something critical of your benefactor?

14 posted on 02/16/2004 11:51:53 AM PST by justlurking
[ Post Reply | Private Reply | To 13 | View Replies]

To: hsmomx3
I have heard that Netscape uses Mozilla. Is that correct?

It's probably more accurate to say that Mozilla "uses" Netscape, depending on your definition of "use".

Mozilla is actually a "fork" of Netscape's browswer. Netscape released the source, and the open source community moved forward with it.

Mozilla is the result. There is a complete suite that is similar to the original netscape, and there are also beta versions of a new browser (Firefox) and email client (Thunderbird) available for download/evaluation.

15 posted on 02/16/2004 11:55:19 AM PST by justlurking
[ Post Reply | Private Reply | To 9 | View Replies]

To: Paleo Conservative
But it's great for cutting down the number of brower sessions on my desktop. I can read muliple threads on Free Republic with only one browser session, and it is easy to shutdown.

You can do the same thing with Mozilla Firefox (and it may be in the earlier versions of Mozilla, too). I really like the "tabbed" browser, as well.

I still have to use IE for a few things, though. I have to use certain plug-ins approximately weekly for my job. But, for everything else I've been using Firefox (it used to be called Firebird).

16 posted on 02/16/2004 11:59:35 AM PST by justlurking
[ Post Reply | Private Reply | To 10 | View Replies]

To: Bobalu
Mozilla Firefox is a great browser. Beats IE .


Find out why people everywhere are switching to Firefox. Be sure not to miss the great Introduction to Firefox.


http://www.mozilla.org/products/firefox/why/
17 posted on 02/16/2004 12:05:45 PM PST by philetus (Keep doing what you always do and you'll keep getting what you always get)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bobalu
Better get rid of IE5 if you use it.... get mozilla or Opera.

I'm on day three of trying mozilla's Camino for MacOS. I really like it!

18 posted on 02/16/2004 12:11:49 PM PST by null and void (Dems say there will be "Armageddon Cuts" in the budget. That sounds like what we've been asking for!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: justlurking
Don't you have anything better to do than harass anyone that happens to post something critical of your benefactor?

Don't you have anything better to do than harass anyone that happens to post something critical of your benefactor?
19 posted on 02/16/2004 12:21:08 PM PST by Bush2000
[ Post Reply | Private Reply | To 14 | View Replies]

To: Cboldt
These days saying something is 'so gay' means it's REALLY lame.

We're taking back the language one word at a time...
20 posted on 02/16/2004 12:22:23 PM PST by null and void (Dems say there will be "Armageddon Cuts" in the budget. That sounds like what we've been asking for!)
[ Post Reply | Private Reply | To 5 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-34 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson