Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Missouri

It's safer, but security holes still affect the new browser. Plus, a worm in iPods.


1. Local Companies

Host Analytics, Inc.
314-588-2121
911 Washington Avenue
St. Louis, MO
AudioVu.com
800-721-1440
200 S. Hanley
St. Louis, MO
Cyber Samurai Marketing, Inc.
314-835-1510
11939 Manchester Rd
St. Louis, MO
Midwest Technology Connection
816-471-3553
410 W. 5th St
Kansas City, MO
Strategic eCommerce Solutions
(314) 966-0900
128 West Monroe Ave.
Saint Louis, MO
Socket Internet
(573) 833-9930
Pocahontas, MO
McM Systems
(660) 269-8088
112 S Williams St
Fayette, MO
Socket Internet
(573) 368-3700
Rolla, MO
Socket
(573) 728-9854
Argyle, MO
Mark Warren Communication
(636) 332-8873
305 N Business Highway 61
Wentzville, MO


2. Introduction

Internet Explorer 7 for Windows XP is finally out. Because it tries to fix or prevent many of the numerous security flaws that hit IE 6, it's arguably the largest bug fix we've seen in quite a while. For that reason alone, I recommend installing the update.

But IE 7 is not a panacea, in part because it still ties in to Windows for some of its work and can therefore pass along threats from buggy parts of the operating system (or other programs). We've seen a number of these types of problems recently, and now three more have been reported.

Less than a day after IE 7's release, Danish security firm Secunia said it had found a proof-of-concept, noncritical bug affecting IE 7. If you browse a malicious site while logged in to another site, an attacker could steal data you have on the logged-in site. Microsoft says the bug actually resides in Outlook Express, but IE 7 can be used as the attack vector, just like IE 6.

You're likewise vulnerable to a nasty, critical Windows bug involving XML, which is commonly used for Web sites and many document types, regardless of whether you use IE 6 or IE 7. Both versions hand off XML processing to Windows proper, where the bug originates. You could be infected with a drive-by download from a malicious Web site if an attacker directs a bunch of garbage data through IE to the newly discovered Windows weak spot. At press time no attacks had yet used this bug, but all currently supported versions of Windows could be hit. If you didn't receive the patch in Automatic Updates, check here.

The new IE does offer more protection than version 6 for another pass-through critical Windows glitch--one that has already proven to be a popular hacker target. This flaw hits the Windows Shell, which displays the Windows user interface. Attackers can employ an ActiveX control to reach the bug via IE (with yet another buffer overflow error) and thereby take over your system. As with the XML bug, all supported versions of Windows are affected.

IE 7 provides additional protection in this case because it displays an opt-in pop-up that requires your approval before running new ActiveX controls. The pop-up won't specifically tell you you're under attack, and if you just click OK as many people are now conditioned to do with many browser notices, you'll get nailed. But it's more protection than you'll get with IE 6, which on an unpatched system will download a malicious payload without warning if you browse a booby-trapped site. Get the fix from here or via Automatic Updates.

Video iPods may Come with Windows Worm

A small number of video iPods picked up an unwelcome tag-along during manufacturing: a Windows worm. The malware doesn't harm the iPod, but once the device hooks up to a PC, the worm can silently wiggle its way into the system--and from there to any linked external storage device, like a thumb drive.

Less than 1 percent of video iPods shipped between September 12 and mid-October carry the worm, but if it infects a PC it can give an attacker full remote control. As a fix, Apple posted links to free trials of popular antivirus apps for cleaning affected computers, and says to use iTunes 7 to wipe and restore an iPod. Apple's bulletin can be found here.

3. New Office Holes

Hackers are using a new batch of critical Office 2000 flaws to bite credulous openers of suspicious e-mail attachments. The holes are less dangerous, but still present, in Office 2003. Keep Office updated through Automatic Updates, or grab the patches here.

4. More Battery Heat

Sony is recalling some 3.5 million laptop batteries worldwide, including those used in its VAIO notebooks, as well as those in models from Fujitsu, Gateway, and Toshiba, because of a minute (but real) risk of overheating and fire. For a full list of recalled models and links to makers' recall sites, click here.

BUGGED?

Found a hardware or software bug? Send an e-mail about it to bugs@pcworld.com.

Stuart J. Johnston is a contributing editor for PC World.

5. Featured Local Company

AudioVu.com

800-721-1440
200 S. Hanley
St. Louis, MO
http://www.audiovu.com

Regional Articles
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Arnold MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Aurora MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Ballwin MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Belton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Blue Springs MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Bolivar MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Bonne Terre MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Boonville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Branson MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Bridgeton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Camdenton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Cameron MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Cape Girardeau MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Carthage MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Chesterfield MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Chillicothe MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Clinton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Columbia MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already De Soto MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Dexter MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Eldon MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Eureka MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Excelsior Springs MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Farmington MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Fenton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Festus MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Florissant MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Fort Leonard Wood MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Fredericktown MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Fulton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Grandview MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Hannibal MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Harrisonville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Hazelwood MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already High Ridge MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Hillsboro MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already House Springs MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Imperial MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Independence MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Jackson MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Jefferson City MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Joplin MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Kansas City MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Kennett MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Kirksville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Lebanon MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Lees Summit MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Liberty MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Marshall MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Marshfield MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Maryland Heights MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Maryville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Mexico MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Moberly MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Monett MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Neosho MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Nevada MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Nixa MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already O Fallon MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Ozark MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Pacific MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Park Hills MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Perryville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Poplar Bluff MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Raymore MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Republic MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Rolla MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Saint Ann MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Saint Charles MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Saint Clair MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Saint Joseph MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Saint Louis MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Saint Peters MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Sainte Genevieve MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Salem MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Sedalia MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Sikeston MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Springfield MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Sullivan MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Troy MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Union MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Warrensburg MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Warrenton MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Washington MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Waynesville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Webb City MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already Wentzville MO
- Bugs and Fixes: Internet Explorer 7 Proves Buggy Already West Plains MO
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Educational Content Home Appliances Real Estate Resources
Business Services Entertainment Home Electronics Software
Career Family Home Services Technology
Cars Fashion Internet Telecommunications
Chamber of Commerce Financial Services Legal Trade Shows
Computer Hardware Franchise Miscellaneous Travel
Construction Health Nightlife Weddings
Education Holidays Online Database World History