ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft IE 5.0 bodges patched

Dave Wilby ZDNet.co.uk

Published: 30 Sep 1999 14:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security vulnerabilities highlighted in Microsoft Internet Explorer 5.0 have now been addressed by the company's online security bulletin service.

The two security holes in IE 5.0 are a further annoyance to Microsoft, which is still patching up unforeseen blunders in version 4 of its ubiquitous browser. This month alone has seen numerous patches posted to prevent possible malicious attacks on users of the earlier version of the software.

The first IE 5.0 problem is connected to an in-built feature called "download behaviour" which allows Web page authors to download files for use in client-side script. Microsoft explains that by design, a Web site should only be able to download files that reside in its own domain. This, it says, prevents client-side code from exposing a user's files to the Web site. However, it now admits that a server-side redirect could be used to bypass this restriction, enabling users' files to be read.

Microsoft says that patch will be delivered shortly, but that in the meantime, users can prevent malicious attacks by disabling Active Scripting.

The second alert features a fix for a problem first highlighted earlier this month that also affects IE 4.01 users. IE 5 incorporates a feature that allows users to export a list of favourite sites to a file, or to import a file of favourite sites. The feature is called ImportExportFavorites, and in theory should only allow particular types of files to be written and to only specific areas of a local drive. However, Microsoft now say that it is possible for a Web-site to invoke this feature, bypass restrictions and write files that could be used to execute system commands. (Quite scary.)

Thankfully several patches are now available for both versions of IE, and both x86 and Alpha processors.

You can get a patch here for 4.01/Intel, here for 4.01/Alpha, here for IE5/Intel, and here for IE5/Alpha.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
32 out of 70 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Oracle DBA with UNIX Immediate Vacancy London/ Croydon 35k

The role is to provide day to day support, troubleshooting, tuning, administration, systems hardening (security), and project work for a wide range ...

SQL Applications Senior Support Cheshire 35k

Liaisons between suppliers, software vendors and other technical resources to resolve technical issues Systems documentation and software/hardware ...

Web Infrastructure Co-ordinator (Linux Web)

Extensive experience in carrying out system updates and applying patches to web based systems. Experience and skills in PHP scripting and Access ...

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains