Wednesday, August 03, 2005 9:23 AM
cmosby
Answer to a browser question..
Ron raised a good question over on his blog, and welcomed me back from vacation.
I forgot to mention that I had a lot of fun on vacation, it was really good to see all the friends we had to leave back in Wa. State. We had really missed them and it felt like we had never left.
To answer Ron’s question about IE 7, it will be never. Too little, too late for Microsoft as far as I am concerned. They should fix IE 6 first, before going in new directions. Here is a excerpt from a recent WindowsSecrets.com column I wrote about this subject:
New JPEG problems in IE discovered
The SecurityFocus Web site posted on July 15 four new IE vulnerabilities. Each of these vulnerabilities involves IE's image rendering library. This affects you when you simply view a JPEG file in IE. For details, see SecurityFocus bulletins 14282, 14284, 14285, and 14286.
These vulnerabilities can make IE crash, at the very least. At worst, they allow the installation of spyware or viruses on a computer. Exploit code has been posted for all of these vulnerabilities, although so far the exploits have only been shown to work on IE 6 SP2. Considering that this version is supposed to be Microsoft's most secure browser, these exploits will more than likely work with previous versions of IE as well.
These exploits are still very new, so information on how to work around them is sketchy. So far there have been no reports of anyone circulating these exploits in the wild, but that could change at any time. I suggest switching to an alternate browser, such as Firefox, until these major vulnerabilities can be patched.
If using another browser is not an option, you could always disable the downloading of pictures in IE. But that wouldn't give you much of an Internet to look at, now would it? At the very least, you should make sure that IE is secured with Brian's recommended configuration, and that you are using at least the recommended Security Baseline (above).
Filed under: Patch Management, Microsoft Windows, On a personal note...., Browser Wars