Advertisement
Promo

Online business Toolkit

Microsoft stomps on new IE bugs

Published: 16 May 2002 08:41 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft urged Windows users to download a fix for Internet Explorer on Wednesday, following the company's announcement that six new flaws had been found in its Web browser.

The software company called three of the flaws critical, but only one of them -- a cross-site scripting error that affects only Internet Explorer 6.0 -- would allow an attacker or a worm to run a program on the victim's computer.

"Two of them are critical because of the possibility of information disclosure," said Christopher Budd, security program manager for the Microsoft security response team. "But they have steep requirements."

The first flaw occurs when the browser sends information within a link to another browser. Known as cross-site scripting, the technique can be abused by an attacker to get the other site to run a program specified by a malicious user. The flaw outlined by Microsoft on Wednesday would require that the attacker either host a Web page with the malicious link or send an HTML command via email.

The two critical flaws that could compromise user information occur because of the way IE handles popular site templates, known as cascading style sheets, and the way it processes cookies. Both require the exact names of files on the target system to work, reducing the risk somewhat.

The other flaws and the patch can be found in the advisory.

Microsoft Windows XP users will automatically be prompted to install the update by the operating system, while users of other Windows variants will have to go to the Windows Update site.

The 2MB download includes all the old repairs for Internet Explorer 5.01, 5.5 and 6.0, plus patches for the latest six holes as well.

In addition to the patches, the software update changes the default settings of the "Restricted Sites" zone to block all frames.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
37 out of 78 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters