ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Online business Toolkit

MS flags Mac IE 5 security gap

Matthew Rothenberg ZDNet.co.uk

Published: 18 May 2000 13:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft acknowledged Wednesday that a potential security gap has resurfaced in the Mac version of Internet Explorer after a three-year hiatus.

"We believe that this is going to affect very few people, but obviously, since it's a security issue, we take it very seriously, and we're working on an update," said Irving Kwong, a product manager with Microsoft's Macintosh Business Unit. However, Kwong said he couldn't specify when the fix would be ready.

The company blamed the flaw -- what it calls a "Java redirect issue" -- on its implementation of Apple's Macintosh Runtime for Java, or MRJ, in the browser.

The glitch, which cropped up under Internet Explorer 3.0 in 1997, resurfaced again in IE 5. "With Internet Explorer 5, when we implemented Apple's MRJ, we tried to create a more secure Java session by offering the whole Secure Sockets Layer," Kwong said. "Doing that, we opened up a hole that was there before."

Microsoft said security would be compromised only under a specific set of conditions: "Our current understanding of the problem is that when an unknowing user visits a Web site with malicious code, the site could download an image from another Web site, such as an intranet that the user has permission to access, without the user's permission." Kwong said a malicious Web developer would need to know details of the exact path within the intranet from that specific user's computer. Users behind a firewall or on a network that employs intelligent authentication are safe from the glitch, he said.

The company recommended that concerned users disable Internet Explorer's use of Java until the problem is fixed.

In the meantime, "we've not seen anybody who's been harmed by this or has been able to exploit it," Kwong said.

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
27 out of 75 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Sentry Posts Blog

Toshiba touts Quantum Key Distribution

Toshiba research scientists have developed a method of distributing quantum keys more efficiently, the company has claimed in a statement: "[Quantum Key Distribution -- ] QKD --... More

Post a comment

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment