| |
|

|
|

|
|
User Controls
|
|
New User
|
|
Login
|
|
Edit/View My Profile
|
|

|
|

|
|

|
|
Active Network
|
|
ActiveMac
|
|
ActiveWin
|
|
ActiveXbox
|
|
Careers
|
|
DirectX
|
|
Downloads
|
|
FAQs
|
|
Interviews
|
|
MS Games & Hardware
|
|
Reviews
|
|
Support Center
|
|
TopTechTips
|
|
Windows 2000
|
|
Windows Me
|
|
Windows Server 2003
|
|
Windows Vista
|
|
Windows XP
|
|

|
|

|
|

|
|
News Centers
|
|
Windows/Microsoft
|
|
Apple/Mac
|
|
Xbox/Xbox 360
|
|
News Search
|
|
XML/RSS Newsfeeds
|
|
Pocket PC Site
|
|

|
|

|
|

|
|
FAQ's
|
|
Windows Vista
|
|
Windows 98/98 SE
|
|
Windows 2000
|
|
Windows Me
|
|
Windows Server 2003
|
|
Windows XP
|
|
Windows 7
|
|
Internet Explorer 6
|
|
Internet Explorer 5
|
|
Xbox 360
|
|
Xbox
|
|
DirectX
|
|
DVD's
|
|

|
|

|
|

|
|
Latest Reviews
|
|
Xbox/Games
|
|
Fable 2
|
|

|
|
Applications
|
|
Windows 7
|
|
IE 8
|
|

|
|
Hardware
|
|
Microsoft Arc Mouse (Red)
|
|

|
|

|
|

|
|
Latest Interviews
|
|
Mike Swanson
|
|

|
|

|
|

|
|
Site News/Info
|
|
About This Site
|
|
Advertise
|
|
Affiliates
|
|
Contact Us
|
|
Default Home Page
|
|
Link To Us
|
Sponsors:
SEO
Search Engine Optimisation
exterminator
lawn care
SEO
Search Engine Optimisation
Search Engine Optimization
Search Engine Marketing
PPC Management
Search Engine Optimization
Search Engine Optimisation
search engine optimisation
Cheap Web Hosting
Webanalyse
online credit card processing
Lenovo Laptops
Text Links
Business Gifts
SEO Services
SEO
cheap websites
Search Engine Optimization
Promotional Pens

|
|
 |
|
 |
|
 |
| Time:
00:00 EST/05:00 GMT | News Source:
ActiveWin.com |
Posted By: Julien Jay |
As we exclusively brought you last week: The "11 February 2002 Cumulative Patch for Internet Explorer" update eliminates all known security vulnerabilities affecting Internet Explorer 6, as well as six new vulnerabilities, and is discussed in Microsoft Security Bulletin MS02-005. Download now to protect your computer from these vulnerabilities, the most serious of which could allow an attacker to run code on your computer. The new breaches fixed are listed below:
- A buffer overrun vulnerability associated with an HTML directive that's used to incorporate a document within a web page. By creating a web page that invokes the directive using specially selected attributes, an attacker could cause code to run on the user's system.
- A vulnerability associated with the GetObject scripting function. Before providing a handle to an operating system object, GetObject performs a series of security checks to ensure that the caller has sufficient privileges to it. However, by requesting a handle to a file using a specially malformed representation, it would be possible to bypass some of these checks, thereby allowing a web page to complete an operation that should be prevented, namely, reading files on the computer of a visiting user's system.
- A vulnerability related to the display of file names in the File Download dialogue box. When a file download from a web site is initiated, a dialogue provides the name of the file and lets the user choose what action to take. However, a flaw exists in the way HTML header fields (specifically, the Content-Disposition and Content-Type fields) are handled. This flaw could make it possible for an attacker to misrepresent the name of the file in the dialogue, in an attempt to trick a user into opening or saving an unsafe file.
- A vulnerability that could allow a web page to open a file on the web site, using any application installed on a user's system. By design, IE should only open a file on a web site using the application that's registered to that type of file, and even then only if it's on a list of safe applications. However,
through a flaw in the handling of the Content-Type HTML header field, an attacker could circumvent this restriction, and specify the application that should be invoked to process a particular file. IE would comply, even if the application was listed as unsafe.
- A vulnerability that could enable a web page to run a script even if the user has disabled scripting. IE checks for the presence of scripts when initially rendering a page. However, the capability exists for objects on a page to respond to asynchronous events; by misusing this capability in a particular way, it could be possible for a web page to fire a script after the page has passed the initial security checks.
- A newly discovered variant of the "Frame Domain Verification" vulnerability discussed in Microsoft Security Bulletin MS01-058. The vulnerability could enable a malicious web site operator to open two browser windows, one in the web site's domain and the other on the user's local file system, and to use the
Document.open function to pass information from the latter to the former. This could enable the web site operator to read, but not change, any file on the user's local computer that could be opened in a browser window. In addition, this could be used to mis-represent the URL in the address bar in a window opened from their site.
This update applies to: Internet Explorer 6, Internet Explorer 5.5 SP2, Internet Explorer 5.5 SP1, and Internet Explorer 5.01 SP2 on Windows 2000 only. The update is already available in many languages, and can be downloaded here:
|
| |
|
#1 By
interdev159 (36 Posts)
at
2/11/2002 9:50:51 PM
|
Yeah! First to download and first to install and first to comment. This took IE 6 to 6.0.2600.0000 (2600? A hidden tribute?).
No problems seen so far, of course I haven't tried it against the alleged "hacks" that didn't seem to work anyway before the update.
|
|
#2 By
AWJulien (407 Posts)
at
2/11/2002 9:53:56 PM
|
|
Nope I was first, cuz I dl and applied the update before posting the news ;) LOL :)
|
|
#3 By
JaggedFlame (2581 Posts)
at
2/11/2002 9:58:51 PM
|
|
An ActiveWin Exclusive, arguments over first installation, and a long-ass article over a security patch? HAHAHAHA
|
|
#4 By
n4cer (2054 Posts)
at
2/11/2002 10:03:56 PM
|
Off Topic: Microsoft has attracted another suitor :)
Immersion is suing MS and Sony over the rumble technology used in the XBOX and PS/PS2 controllers.
http://www.teamxbox.com/news.php?id=2584
This post was edited by n4cer on Monday, February 11, 2002 at 22:04.
|
|
#5 By
rseiler (122 Posts)
at
2/11/2002 10:11:37 PM
|
|
I posted this in the other thread on this subject before the new announcement was made here, but why is it that the files inside the patch are dated 1/15 at the latest? Last-minute fixes?
|
|
#6 By
Anonymous (12.243.105.19)
at
2/11/2002 10:15:55 PM
|
|
If you actually read the Security Buleltin, it told you how to check that the patch was installed, open the about dialog in IE, look where it says "Update Versions" and look for Q316059
|
|
#7 By
interdev159 (36 Posts)
at
2/11/2002 10:33:12 PM
|
|
Julien, you don't count. I will have to say that I did get a crash out of IE a few minutes ago, which is the first in a long time. I think there might have been a Java applet on the page that I was trying to view. :)
|
|
#8 By
sodablue (5245 Posts)
at
2/11/2002 10:42:23 PM
|
I don't believe any of you. This update clearly does not exist and is a hoax. :)
|
|
#9 By
n4cer (2054 Posts)
at
2/11/2002 11:21:33 PM
|
#1
2600 is Windows XP's build number. They made IE6 for it first, then ported to the downlevel platforms. The patch was probably set to bring the other versions in line with XP.
|
|
#10 By
Anonymous (129.2.232.67)
at
2/11/2002 11:37:38 PM
|
|
Anyone noticing that IE loads a lot slower now?
|
|
#11 By
Anonymous (139.169.166.61)
at
2/11/2002 11:39:05 PM
|
As we exclusively brought you last week: The "11 February 2002 Cumulative Patch for Internet Explorer"
AT LAST !!!!! WOOHOO !!!!!
*cough*
|
|
#12 By
interdev159 (36 Posts)
at
2/11/2002 11:53:07 PM
|
|
I don't think it loads slower, but I did find a bug. Whenever I click on the little box with the "x" in the upper right hand corner of the window, IE goes away and I have to start it again. I wonder if the "security experts" that found all the problems have found that one yet? Heh. I'm sooo much better than those guys.
|
|
#13 By
Tegument (154 Posts)
at
2/12/2002 12:52:13 AM
|
|
hmmm...when i try to execute it, it tells me I have to have ie6 installed...which I do...I have 6.0.2813.3000 w/ sp1 from last week....this happening 2 ne1 else?
|
|
#14 By
BobSmith (3719 Posts)
at
2/12/2002 1:20:06 AM
|
|
sp1? of IE6 or WinXP? I think I'm missing something Tegument.
|
|
#15 By
Tegument (154 Posts)
at
2/12/2002 1:36:50 AM
|
bobsmith - yeah, ie6 sp1, see below:
New Beta Build of Internet Explorer 6.0 Service Pack 1 Released to Testers
Time: 12:33 EST/17:33 GMT 2/5/2002 | News Source: E-Mail | Posted By: Byron Hinson
The Microsoft Internet Explorer development team has just released a new English beta build 1330 of Internet Explorer 6.0 Service Pack 1, that is strictly reserved to the lucky Microsoft beta-testers. As the first beta of the service pack had hardly any new features, we will guess that the beta 2 release hasn't added thing special apart from bug fixes either.
|
|
#16 By
BobSmith (3719 Posts)
at
2/12/2002 1:40:49 AM
|
|
gotcha, thanks for the clarification. I was wondering if you had an advanced IE6 with .NET server or something.
|
|
#17 By
BobSmith (3719 Posts)
at
2/12/2002 1:42:13 AM
|
|
Tegument, my guess would be that these fixes are included in sp1 which you've already installed.
|
|
#18 By
Anonymous (64.230.74.120)
at
2/12/2002 6:50:25 AM
|
|
#13 same with me
|
|
#19 By
RoySalisbury (70 Posts)
at
2/12/2002 11:51:49 AM
|
I have looked, and I don't see anywhere that it says it's NOT for Windows XP versions that have IE6. What I am reading here is that this "update/patch" just brings the rest of the IE6 world into line with the version that was released with XP. Is this the case?
I have noticed that the update/patch is not on the "windows update" site for XP or 2000.
Is MS just trying to confuse people with this or what?
|
|
#20 By
Anonymous (207.218.247.206)
at
2/13/2002 7:21:06 AM
|
Now is seems the web pages try to load to quickly or vice versa. I have been to several sites where the page will not load immediately. Only when I refresh does the page load.. Any ideas..
|
|
#21 By
Anonymous (209.87.57.253)
at
2/14/2002 12:39:17 PM
|
We can confirm that the new patch on IE crashes consistently on our Java Applet. :( :( :( :(
We're advising our users not to upgrade until we can figure it out.
|
|
#22 By
Anonymous (61.11.24.145)
at
2/16/2002 5:20:40 AM
|
I had installed the patch...and my outlookexpress crashed.....how can i revert ? no uninstallationj options....please help me out.....please.....please......
jmathew@www.com
|
|
#23 By
lushidDircuri (29 Posts)
at
11/30/2008 2:04:50 AM
|
I finally got tired of getting virus and adware all the time from
using different software to get my mp3s from so I started to pay for
all my music on itunes, then last week my brother in Vegas shows me a
link to this site called http://www.PayZeroMusic.com where he gets all
his stuff from daily, totally free, he is a dj and uses the site to
get all his new stuff and classics.
Ever since he showed me I have been hooked, its super fast to download
any songs or even full albums,they even have a play button beside each
song to hear it before downloading and also have an online playlist, I
loaded up my favorite 60 songs into it and now I just log in from anywhere
and play all my songs, the guys at work are totally hooked on the site
like I now am and I wanted to share the link with you all, remember it
is 100% free, nothing to ever pay for there.
http://www.PayZeroMusic.com
|
|
#24 By
vaksnansabs (13 Posts)
at
12/3/2008 4:15:27 AM
|
Hello found a wonderfull website that has information on all types of snakes.
If you are a snake lover like me then you will find the website really interesting .
Click the link <a href=http://www.petsnakesforsale.info-junction.net>What Do Garden Snakes Eat</a>
Thanks
|
|
#25 By
Odorgoadodo (18 Posts)
at
12/6/2008 5:42:47 PM
|
Hello All, Found this method to get free gold membership of Adult Friend Finder.
Some one told me about this. Have tested it and works. Perfectly legit way to get the gold membership.
You can see the details here
<a href=http://freeadultfriendfindergoldmembership.blogspot.com/>How To Get Adult Friend Finder Gold Membership</a>
Hope it helps you if you are looking to get one.
Take Care
|
|
|
 |
|