The Active Network
ActiveWin Anonymous | Create a User | Reviews | News | Forums | Advertise | VBA in Excel | Users Online: 0  
 

neowin.net

Amazon.com

  *  

  Critical Internet Explorer 6.0 Update Finally Available (Microsoft Security Bulletin MS02-005)
Time: 00:00 EST/05:00 GMT | News Source: ActiveWin.com | Posted By: Julien Jay

As we exclusively brought you last week: The "11 February 2002 Cumulative Patch for Internet Explorer" update eliminates all known security vulnerabilities affecting Internet Explorer 6, as well as six new vulnerabilities, and is discussed in Microsoft Security Bulletin MS02-005. Download now to protect your computer from these vulnerabilities, the most serious of which could allow an attacker to run code on your computer. The new breaches fixed are listed below:

  • A buffer overrun vulnerability associated with an HTML directive that's used to incorporate a document within a web page. By creating a web page that invokes the directive using specially selected attributes, an attacker could cause code to run on the user's system.
  • A vulnerability associated with the GetObject scripting function. Before providing a handle to an operating system object, GetObject performs a series of security checks to ensure that the caller has sufficient privileges to it. However, by requesting a handle to a file using a specially malformed representation, it would be possible to bypass some of these checks, thereby allowing a web page to complete an operation that should be prevented, namely, reading files on the computer of a visiting user's system.
  • A vulnerability related to the display of file names in the File Download dialogue box. When a file download from a web site is initiated, a dialogue provides the name of the file and lets the user choose what action to take. However, a flaw exists in the way HTML header fields (specifically, the Content-Disposition and Content-Type fields) are handled. This flaw could make it possible for an attacker to misrepresent the name of the file in the dialogue, in an attempt to trick a user into opening or saving an unsafe file.
  • A vulnerability that could allow a web page to open a file on the web site, using any application installed on a user's system. By design, IE should only open a file on a web site using the application that's registered to that type of file, and even then only if it's on a list of safe applications. However, through a flaw in the handling of the Content-Type HTML header field, an attacker could circumvent this restriction, and specify the application that should be invoked to process a particular file. IE would comply, even if the application was listed as unsafe.
  • A vulnerability that could enable a web page to run a script even if the user has disabled scripting. IE checks for the presence of scripts when initially rendering a page. However, the capability exists for objects on a page to respond to asynchronous events; by misusing this capability in a particular way, it could be possible for a web page to fire a script after the page has passed the initial security checks.
  • A newly discovered variant of the "Frame Domain Verification" vulnerability discussed in Microsoft Security Bulletin MS01-058. The vulnerability could enable a malicious web site operator to open two browser windows, one in the web site's domain and the other on the user's local file system, and to use the Document.open function to pass information from the latter to the former. This could enable the web site operator to read, but not change, any file on the user's local computer that could be opened in a browser window. In addition, this could be used to mis-represent the URL in the address bar in a window opened from their site.

This update applies to: Internet Explorer 6, Internet Explorer 5.5 SP2, Internet Explorer 5.5 SP1, and Internet Explorer 5.01 SP2 on Windows 2000 only. The update is already available in many languages, and can be downloaded here:

Read Only Comments
Return to News
  Displaying Comments 1 through 9 of 9
  This is an archived static copy of ActiveWin.com.
#1 By 2459 (66.25.124.8) at Monday, February 11, 2002 10:03:56 PM
Off Topic: Microsoft has attracted another suitor :)

Immersion is suing MS and Sony over the rumble technology used in the XBOX and PS/PS2 controllers.

http://www.teamxbox.com/news.php?id=2584


This post was edited by n4cer on Monday, February 11, 2002 at 22:04.

#2 By 3384 (12.224.50.203) at Monday, February 11, 2002 10:11:37 PM
I posted this in the other thread on this subject before the new announcement was made here, but why is it that the files inside the patch are dated 1/15 at the latest? Last-minute fixes?

#3 By 135 (208.50.201.48) at Monday, February 11, 2002 10:42:23 PM
I don't believe any of you. This update clearly does not exist and is a hoax. :)

#4 By 2459 (66.25.124.8) at Monday, February 11, 2002 11:21:33 PM
#1
2600 is Windows XP's build number. They made IE6 for it first, then ported to the downlevel platforms. The patch was probably set to bring the other versions in line with XP.

#5 By 10 (24.17.9.97) at Tuesday, February 12, 2002 12:52:13 AM
hmmm...when i try to execute it, it tells me I have to have ie6 installed...which I do...I have 6.0.2813.3000 w/ sp1 from last week....this happening 2 ne1 else?

#6 By 1845 (12.254.163.35) at Tuesday, February 12, 2002 01:20:06 AM
sp1? of IE6 or WinXP? I think I'm missing something Tegument.

#7 By 10 (24.17.9.97) at Tuesday, February 12, 2002 01:36:50 AM
bobsmith - yeah, ie6 sp1, see below:

New Beta Build of Internet Explorer 6.0 Service Pack 1 Released to Testers

Time: 12:33 EST/17:33 GMT 2/5/2002 | News Source: E-Mail | Posted By: Byron Hinson

The Microsoft Internet Explorer development team has just released a new English beta build 1330 of Internet Explorer 6.0 Service Pack 1, that is strictly reserved to the lucky Microsoft beta-testers. As the first beta of the service pack had hardly any new features, we will guess that the beta 2 release hasn't added thing special apart from bug fixes either.


#8 By 1845 (12.254.163.35) at Tuesday, February 12, 2002 01:40:49 AM
gotcha, thanks for the clarification. I was wondering if you had an advanced IE6 with .NET server or something.

#9 By 1845 (12.254.163.35) at Tuesday, February 12, 2002 01:42:13 AM
Tegument, my guess would be that these fixes are included in sp1 which you've already installed.



 

  *  
  *   *
 
replica watches