Latest IE Patch Can Crash Browser
Microsoft advises Webmasters to change sites' use of VB script and avoid problem.
Joris Evers, IDG News Service
Microsoft's latest security patch for Internet Explorer causes the Web browser to crash when viewing Web pages that contain a certain VBScript directive, several IE users have found. Microsoft acknowledges the problem and says Web site administrators will need to take action.
"This issue does not pose a security threat to users. This issue affects stability. Normal operation can be restored by restarting IE," Microsoft said in a statement Friday. "Microsoft Product Support Services has been working with customers to implement a workaround that addresses a problem in which patched IE browsers could crash when viewing certain pages containing a specific VBScript directive."
The way to fix the problem in the short term will be to tweak the coding on Web pages that contain this directive, called the execScript directive, Microsoft said. However, Microsoft is working on an updated patch, but does not know when that will be released. The latest patch can be downloaded from Microsoft's site. In postings to Microsoft's discussion groups, users had earlier pinpointed the execScript directive as the culprit.
"The workaround is one that site operators would implement on their ASP (Active Server Page) pages. End-users need not do anything," Microsoft said, adding that a knowledge base article explaining the issue and the workaround procedure will be posted to Microsoft.com shortly.
Problems Reported
One Dutch IE user on Friday said his patched Web browser crashed when accessing the Web JetAdmin remote management tool for Hewlett-Packard printers.
"Sadly, the patch removes functionality in IE. I installed the patch on my IE 5 system, but removed it immediately by installing a complete new version of IE 6. The HP administrator page on our LAN did not work on the patched system, but did work on unpatched systems," said Jean van Laarhoven, systems manager for a part of Amsterdam's city government.
Internet advertising company DoubleClick advised its customers in an e-mail not to install Microsoft's patch, a DoubleClick spokesperson said Friday. DoubleClick's ad management system is accessed through the Web and relies on scripting. Two European DoubleClick users, who requested anonymity, confirmed that IE crashed when they tried to access the DoubleClick system after patching their browser.
Microsoft released the "cumulative" patch that fixes six holes in IE versions 5.01, 5.5, and 6.0 on Monday. The software maker gave the patch a "critical" rating and urged all users to immediately install it. The set of patches fixes holes that could allow an attacker to take control over a user's computer.
Full Windows 7 coverage
Laptop Showcase
Dell Fast Track
-
Free Next Day Business Shipping on Dell's Most Popular Systems
Over 35% off Dell’s most popular systems. Delivered in 48 hours with free next business day shipping! Ends 12/22 at 3 PM CST
People who read this also read:
Best Prices on System Utilities
Dragon NaturallySpeaking 10 Standard (Full Product)Price: $64.99
Parallels Desktop 4.0 for Mac (Full Product)Price: $49.99
Norton Partition Magic 8.0 Rev1RetailPrice: $49.99
Dragon Naturally Speaking 10 Legal - UpgradePrice: $149.99
2009 ProfessionalPrice: $29.50
Dragon NaturallySpeaking Preferred 10 (Upgrade)Price: $135.90
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage








