Subscribe

Critical IE vulnerability identified

By Damian Clarkson, ITWeb junior journalist
Johannesburg, 10 Jan 2005

Critical IE vulnerability identified

Internet Explorer 6 users are being warned about a critical vulnerability that could allow hackers to execute spyware and pornography diallers - even if the SP2 patch has been installed, IDM reports.

According to security company Secunia, users should disable IE`s Active X support in order to prevent the problem from happening until Microsoft creates a suitable patch to match the problem.

Staff at Secunia said Microsoft had known about the vulnerabilities for the last two months, and they are surprised that it has not released patches yet for them.

Microsoft said the reason for the delay is because it is making sure that the patches are robust enough to completely stop the problem.

Portable tech to grow in 2005

Portable media devices are set for a big year, as they get smarter and more connected, BBC reports.

Last year saw the emergence of portable media players, such as the Windows-based Creative Zen portable media player, the Samsung Yepp, the iRiver PMC-100, and the Archos AV400 series among others. And the trend is set to continue, says Archos chief Henri Crohas.

"Consumers are showing a great thirst for devices that store all their media in one place for anywhere access. And now those consumers can stay connected and productive at the same time."

Archos launched the latest range of its Linux-based portable media devices - which features built-in Wi-Fi capabilities - at the Consumer Electronics Show in Las Vegas on Friday, says Crohas.

The focus for the device is to be the second gadget in people`s pockets, after the mobile phone, Crohas added.

Firms report new Mozilla security flaws

Security firms have identified three new security flaws in various versions of the Mozilla and Firefox Web browsers and Mozilla`s Thunderbird e-mail client, although none are considered critical.

Polish firm iSEC Security Research reported a flaw in the way Mozilla processes the NNTP (news) protocol, creating a buffer-overflow vulnerability. According to NewsFactor.com, the vulnerability is found in versions of Mozilla prior to 1.7.5, as well as Firefox versions prior to 1.0.

Secunia Research discovered another vulnerability in Mozilla and Firefox that can be exploited by malicious people to spoof the source displayed in the Download Dialog box. According to the company`s Website, the problem is that "long sub-domains and paths aren`t displayed correctly, which therefore can be exploited to obfuscate what is being displayed in the source field of the Download Dialog box."

The vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0.

Security firm ptraced.net reports that temporary files in Mozilla`s Thunderbird 0.8 and 0.9.3 e-mail clients are stored with predictable names in a format that can be read by an intruder, which could potentially expose a user to risk.

Philips DVD burner also plays CDs

Philips has unveiled a computer disc drive that can burn and play CDs and DVDs in three different formats, including Blu-ray.

According to Daily Times, the announcement comes as various electronic giants compete for support of their respective DVD standards. Philips, HP, Sony and Dell are all supporting the Blu-ray format, which offers up to 50 gigabytes of storage space on a disc.

However, Toshiba and Sanyo are pushing the HD (high definition) DVD standard, which they have developed. While it offers less storage capacity, inventors say it is cheaper and will be ready soon.

Philips` new drive will be presented at the Consumer Electronics Show this week, and will be commercially available in the second half of 2005.

Six Apart acquires blog software competitor

Blog software seller Six Apart has acquired Danga Interactive for an undisclosed sum, bringing its total user base to more than 6.5 million.

Six Apart CEO Barak Berkowitz says the merger provides an opportunity for the company to reach a wider array of bloggers. Danga Interactive is the operator of the LiveJournal blogging service, whose users tend to be younger.

According to TechWeb, the merger further validates blogs as a significant channel for online publishing, business communications, and advertising sales.

An American Life Project survey found that 7% of US adults have created a blog, while 27% of Internet users read blogs.

Share