Recent updates to IE contain a serious regression that leaves systems once more vulnerable to a flaw fixed more than two years ago, according to security researchers. The vulnerability, which involves how IE processes XML files, gives rise to information disclosure risks. The security bug was patched and closed back in Aug 2002, six months after Microsoft was initially notified about it by Israeli firm GreyMagic Software, which discovered the problem. Microsoft rated the vulnerability as "moderate" when it fixed the flaw as part a cumulative update (MS02-047) to IE issued on August 22 2002.

You can view the original article here...
http://security-focus.com/news/9722