ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

IE has another megapatch

John McCormick

Published: 28 May 2002 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Within hours of Microsoft's release of MS02-023, Israeli-based GreyMagic sent me an e-mail indicating that there were some mistakes in the text of the security bulletin and explaining why the patch only partially fixed one of the problems.

New threats
This cumulative patch fixes a number of IE vulnerabilities discovered up to this point and addresses six new threats.

The first of the new threats is "Cross-site Scripting in Local HTML Resource" (CAN-2002-0189). Microsoft says that this problem could cause a script to run in the local computer zone as if the user activated it.

GreyMagic contradicted Microsoft's statement that this is "a cross-site scripting vulnerability in a Local HTML Resource," explaining that the problem is actually in the way dialogArguments' security settings are bypassed.

GreyMagic also pointed out that Microsoft is incorrect in saying that this problem is limited to IE 6 and claims that the same problem is found in IE 5 and IE 5.5. Since this cumulative patch doesn't address the problem in those versions, users are still vulnerable even after applying this patch.

GreyMagic reported that "Microsoft did not understand the problem. They only patched a symptom of this vulnerability, not its root cause. As a result of that incomplete 'patch,' IE 5 and IE 5.5 are still very much vulnerable to this attack in other resources." The company has posted a demonstration on its Web site.

Another vulnerability is "Local Information Disclosure Through HTML Object" (CAN-2002-0191). This vulnerability in HTML objects' CSSes could allow an attacker to read but not modify or delete data on a user's system. The attack requires that the user visit a Web site or open an HTML e-mail containing the specially crafted exploit code.

The "Information Disclosure Vulnerability Cookie Scripts" threat (CAN-2002-0192) could allow a Web site to access cookies it shouldn't have access to.

The "Zone Spoofing Through Malformed Web Page" vulnerability (CAN-2002-0190) could, in rare cases, allow malicious Web pages to be treated as if they were in the Trusted Sites zone.

The two newly discovered variations of Content Disposition variants (CAN-2002-0193 and CAN-2002-0188) are a new twist on a problem which Microsoft says was addressed in the cumulative patch supplied with MS01-058. The new problems affect the way IE handles downloads when there are intentionally malformed Content-Disposition and Content-Type headers.

Note
"CAN" numbers (e.g., CAN-2002-0188) indicate "candidate" status for the vulnerability and means that they are still subject to review by the Mitre CVE Editorial Board. CAN and CVE designations are intended to make it easier to identify specific vulnerabilities and prevent confusion among different threats.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
145 out of 299 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Related Jobs

Test Analyst - Consultancy - Central London - Contract

You will be responsible for analysing and understanding new and existing software components and requirements, gathering test requirements and ...

Senior Level Windows Engineer/Architect (Design,Build,AD,Scripting)

The candidate will be providing 3rd line engineering/architecture, hardware/software evaluation, automation using scripts & projects. Ideal ...

Integration Application Designer

As Application Designer, your key responsibilities will include: - Undertaking specific, complex development project activities Preparing detailed ...

Featured Talkback

Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Vista Upgrade Blog

XP survival, from one horses mouth, an...

Hi everyone....for those that need more information on XP survival, I have pasted this open letter from Bill Veghte, senior vice president of microsoft, found on microsoft .com. Hope... More

2 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment