IE7 locked and loaded
“I’m out there, Jerry! And, I’m lovin’ every minute of it!”
I downloaded IE7 this morning and installed it on my computer. I’ve been extremely happy with the previous public betas, so I’m sure I’ll be happy with the release. We’ll see.
BTW: There’s already rumors of a IE7 vulnerability. It wouldn’t surprise me if some Firefox folks held news of this vulnerability until IE7 was released.
Details of the vulnerability as follows:
Secunia Advisory: SA22477
Release Date: 2006-10-19
Critical: Less critical
Impact: Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Description:
A vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.
Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected.
Solution:
Disable active scripting support.
Link:
http://secunia.com/advisories/22477/