Advertisement
Promo

Online business Toolkit

Security hole in IE5, patch in progress

Grant Dubois ZDNet.co.uk

Published: 14 Oct 1999 10:46 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft this week said a security hole in its Internet Explorer 5.0 browser could enable Web site operators to read files on visiting users' PCs.

According to a security alert issued by Microsoft, Web site operators can read files only if they already know the name of the file and the folder in which it resides. The security hole does not allow malicious operators to list the contents of folders, create, modify or delete files, or have any administrative control over other people's PCs.

Microsoft is currently developing a patch, but until it is ready, the company recommends users only add Web sites they trust to the "Trusted Zone" in IE 5.0 and disable Active Scripting in the "Internet Zone", where all Web sites exist. These actions will provide full functionality for all trusted sites, while preventing untrusted sites from being able to exploit the security hole, officials said.

The security alert states that the problem exists only if Active Scripting is enabled in the security zone that the Web site resides in. Each zone -- Internet Zone, Local Intranet Zone (where all local Web sites exist), Trusted Zone and Restricted Zone (where untrusted Web sites reside) -- has its own set of allowed and disallowed actions, which users can customize.

For more information, see Microsoft's security alert . The patch will be available at windowsupdate.microsoft.com, and Active Scripting will be required to install it.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
47 out of 94 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters