Microsoft, Mozilla, and Apple: The BugBlog Report 10/2/06

Part of: BugBlog

Here are some of the most significant bugs from the past week in the BugBlog:

Microsoft has issued an out-of-cycle security bulletin (meaning they didn't wait for Patch Tuesday) for the VML Buffer Overrun bug in Microsoft Internet Explorer. This bug was being actively exploited by hostile web sites, and could completely take over your computer, as shown in the 9/26 and 9/20 BugBlogs. Microsoft has a patch.

There is a bug in Mozilla Firefox's implementation of JavaScript, and it may allow malicious websites to run their code on your computer due to a stack overflow error. The bug was found by Mischa Spiegelmock, of SixApart, and Andrew Wbeelsoi. A spokesperson for Mozilla said that the issue looks genuine. Also, enough details were disclosed during the presentation that attacks may be mounted.

There is a bug in the way that Mac OS X 10.4.x computers view JPEG2000 images. An attacker may be able to construct one of these images that can either crash the application viewing it, or run hostile code on your machine. Apple has fixed this in the Security Update 2006-006 and have also patched it in Mac OS X 10.4.8. They credit Tom Saxton of Idle Loop Software Design for finding this bug.

Article tags

Spread the word
Bookmark and Share
Profile image for bruce-kratofil

Article Author: Bruce Kratofil

Bruce Kratofil blogs on bugs and other things that can go wrong with your computer at The BugBlog, and writes about computers and economics at BJK Research

Visit Bruce Kratofil's author pageBruce Kratofil's Blog

Read comments on this article, and add some feedback of your own
  • No image found
  • No image found
  • No image found
  • No image found
  • No image found
  • No image found

Article comments

  • 1 - Bruce Kratofil

    Oct 03, 2006 at 3:01 pm

    There appears to be a major retraction in the claims about this JavaScript bug in Mozilla. It appears that all the bug will do is crash the browser -- so far, no one has gotten it to run malicious code. Mozilla will continue to investigate.

Add your comment, speak your mind

Personal attacks are NOT allowed.
Please read our comment policy.
Please preview your comment.

blogcritics lists for May 17, 2013

fresh articles Most recent articles site-wide

fresh comments Most recent comments site-wide

most comments Most comments in 24hrs

top writers Most prolific Blogcritics for April

top commenters Most prolific Commenters in 24 hrs