Microsoft has confirmed that it will release a patch released last week because it can cause a browser crash when users visit some websites. Patch software in the MS06-042 Security Bulletin fixed eight defects in IE 5.01 and 6, according to external reports. On Wednesday, a Microsoft Security Manager said that Microsoft will re-design the patch and then re-release it on March 13, August 22. Mike, the operation manager at the Microsoft Security response center, wrote in his blog that we have updated the MS06-042 Security Bulletin to give users an idea of the problems they may encounter after installing the patch.
When you access a website that supports both compression and HTTP 1.1, running IE 6 SP1 on Windows XP SP1 and Windows 2000 will crash. Before the MS06-042 is re-released, users need to run a temporary patch software from Microsoft, but users cannot download the patch software, need to contact Microsoft's service center by phone, obtain the temporary patch.
Despite the crash of some users' IE, Microsoft still recommends that users install MS06-042 patches. Mike said that since it fixes many bugs, we still recommend that you install it.
IE 6 running on Windows XP SP2, Windows Server 2003, or Windows System 2003 SP1 is not affected by this issue, and you do not need to reinstall the patch software released next week.
In the patch software released in August 8, the IE issue is not the only one Microsoft must address. Microsoft updated its MS06-040 Security Bulletin on Tuesday, proving that software that requires a lot of continuous memory might crash after installing the patch, such as Microsoft Business Solutions navivision 3.70. Microsoft has also created a temporary patch, and users also need to obtain the temporary patch by phone.
Adion, project manager at Microsoft's security response center, said in a blog last week that the MS06-040 had fixed a defect in server service, however, it does not fix the Denial-of-Service attack defects I mentioned earlier. We are still developing issues that fix this denial of service attack defect, which we learned after the test cycle of the MS06-040. Considering the importance and potential security of the Defects Corrected by the MS06-040, we think it is very important to release it as early as possible. We are still developing patch software to fix this problem. Once the quality standards are met, we will release this patch software.