John, still convinced that browsers are perfectly safe? I never said browsers were perfectly safe... I said that cookies are not a security loophole, and cannot steal security info.
And even this bug is not really a security threat. All that will happen is that the browser will hang b/c it writes outside of its memory block. And as far as beginning to write a virus at the 257 character... i doubt someone could write byte codes of an executable file to the local broswer, since you are limited to the standard ascii character set. And even if you did manage to get something that would actually function into memory, A) The machine would have hung already - as soon as the browser read in more than it could handle, it would go kerplunk, and B) There is no way to execute it.
So basically, all this bug is, is that, a bug that causes IE to crash.
I will say, that it is quite possible for IE to have some real security loopholes, but most seem to have been patched up by now.
reguards, JohnCov |