Advertisement
Promo

Office applications Toolkit

IE has another megapatch

John McCormick

Published: 28 May 2002 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Within hours of Microsoft's release of MS02-023, Israeli-based GreyMagic sent me an e-mail indicating that there were some mistakes in the text of the security bulletin and explaining why the patch only partially fixed one of the problems.

New threats
This cumulative patch fixes a number of IE vulnerabilities discovered up to this point and addresses six new threats.

The first of the new threats is "Cross-site Scripting in Local HTML Resource" (CAN-2002-0189). Microsoft says that this problem could cause a script to run in the local computer zone as if the user activated it.

GreyMagic contradicted Microsoft's statement that this is "a cross-site scripting vulnerability in a Local HTML Resource," explaining that the problem is actually in the way dialogArguments' security settings are bypassed.

GreyMagic also pointed out that Microsoft is incorrect in saying that this problem is limited to IE 6 and claims that the same problem is found in IE 5 and IE 5.5. Since this cumulative patch doesn't address the problem in those versions, users are still vulnerable even after applying this patch.

GreyMagic reported that "Microsoft did not understand the problem. They only patched a symptom of this vulnerability, not its root cause. As a result of that incomplete 'patch,' IE 5 and IE 5.5 are still very much vulnerable to this attack in other resources." The company has posted a demonstration on its Web site.

Another vulnerability is "Local Information Disclosure Through HTML Object" (CAN-2002-0191). This vulnerability in HTML objects' CSSes could allow an attacker to read but not modify or delete data on a user's system. The attack requires that the user visit a Web site or open an HTML e-mail containing the specially crafted exploit code.

The "Information Disclosure Vulnerability Cookie Scripts" threat (CAN-2002-0192) could allow a Web site to access cookies it shouldn't have access to.

The "Zone Spoofing Through Malformed Web Page" vulnerability (CAN-2002-0190) could, in rare cases, allow malicious Web pages to be treated as if they were in the Trusted Sites zone.

The two newly discovered variations of Content Disposition variants (CAN-2002-0193 and CAN-2002-0188) are a new twist on a problem which Microsoft says was addressed in the cumulative patch supplied with MS01-058. The new problems affect the way IE handles downloads when there are intentionally malformed Content-Disposition and Content-Type headers.

Note
"CAN" numbers (e.g., CAN-2002-0188) indicate "candidate" status for the vulnerability and means that they are still subject to review by the Mitre CVE Editorial Board. CAN and CVE designations are intended to make it easier to identify specific vulnerabilities and prevent confusion among different threats.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
145 out of 299 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:













Video icon

Video

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

Shibley R Shibley R

Eigg

Sunday 27 December 2009, 1:04 PM

1 comment
Tezzer Tezzer

Nice to see but...

Saturday 26 December 2009, 10:28 AM

5 comments
NoThomas NoThomas

Sure I can

Saturday 26 December 2009, 2:01 AM

11 comments

Vista Upgrade Blog

How to Upgrade From Windows Vista to W...

Did you get the news? Microsoft has unzipped its kitty and kept its latest, supposedly the best, offering on display. This is the brand new version of Microsoft operating system, named... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters