On August 15, 2006, Microsoft announced that it will release a new version of security update 918899 (MS06-042) on August 22, 2006. This new version was to address this problem for customers who use Internet Explorer 6 Service Pack 1. Because of an issue that was discovered in final testing, Microsoft will not release the new version of security update 918899 on August 22, 2006. Microsoft will release this update for Internet Explorer 6 Service Pack 1 when it meets an appropriate level of quality for broad distribution.
Microsoft is also aware of public reports that this issue could lead to a buffer overrun condition for customers who use Internet Explorer 6 Service Pack 1 and who have applied security update 918899. We are not aware of attacks that try to use the reported vulnerability at this point, nor are we aware of customer impact at this point. Microsoft is aggressively investigating the public reports.
Only customers who use Internet Explorer 6 SP1 are affected. All other customers should continue their deployments of security update 918899. Customers who use Internet Explorer 6 SP 1 should continue their deployment of security update 918899 and follow the existing guidance that is provided in Microsoft Knowledge Base article 923762. These customers should also follow the suggestions that are described in the "Suggested Actions" section
of Microsoft Security Advisory 923762.