ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Office applications Toolkit

IE has another megapatch

John McCormick

Published: 28 May 2002 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Applicability
Microsoft Internet Explorer releases 5.01, 5.5, and 6.0 are affected by these threats. Microsoft no longer supports earlier versions of IE, although they could be affected by these flaws.

Risk level -- critical
Microsoft rates a number of the covered vulnerabilities as critical and recommends that any users of IE 5, IE 5.5, or IE 6 apply this patch immediately.

Cross-Site Scripting in Local HTML Resource is critical for IE 6.0 clients and moderate for servers. According to Microsoft, this poses no threat to IE 5.01 and IE 5.5, but if GreyMagic is correct -- and as far as I can determine, it is -- IE 5.01 occasionally and IE 5.5 always remain vulnerable to this threat even after this patch.

The Local Information Disclosure Through HTML Object threat affects IE 5.01, IE 5.5, and IE 6.0 and is critical for client systems and moderate for servers.

The Information Disclosure Vulnerability Cookie Scripts threat affects IE 5.5 and IE 6.0 and is critical for client systems and moderate for servers. According to Microsoft, IE 5.01 is not vulnerable.

The Zone Spoofing Through Malformed Web Page flaw is low for all. The Content Disposition variants are moderate for IE 5.01 and 6.0 servers and clients and pose no risk for IE 5.5 client or server.

Mitigating factors
Cross-Site Scripting in Local HTML Resource
Microsoft says that there is no way to automate this attack because it requires the user to click on a hyperlink. However, according to GreyMagic, "This is simply wrong; the user doesn't have to click anything for this issue to be exploited. It can run automatically." Microsoft also indicated that correctly updated and patched versions of Outlook, Outlook Express, and Outlook 2002 SP1 now open all HTML code in the Restricted Sites Zone, which would block this attack.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
145 out of 299 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Featured Talkback

In association with Intel
Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Discussions

roger andre roger andre

Skype Spying Debacle

Sunday 12 October 2008, 6:43 PM

1 comment
bagalibaba bagalibaba

CHEAP SELL, TOP QUALITY

Sunday 12 October 2008, 4:12 PM

1 post
bagalibaba bagalibaba

CHEAP SELL, TOP QUALITY

Sunday 12 October 2008, 3:35 PM

1 post
bagalibaba bagalibaba

CHEAP SELL, TOP QUALITY

Sunday 12 October 2008, 3:32 PM

1 post

Vista Upgrade Blog

Vista - Still Running and Stable After...

Six weeks ago, when I wrote Renewed Adventures with Vista, I wondered if Microsoft had finally managed to fix it sufficiently that I wouldn't be forced to give up on it after a few... More

Post a comment

Official MS Windows 7 Bloggers

Check this out: http://blogs.msdn.com/e7...spx Its an official blog "Engineering Windows 7" Nothing. That's what is revealed. Until there is real... More

5 comments

Microsoft's Mojave just a desert vista

It didn't seem fair to wade into Microsoft's “Mojave Experiment” advert quite so soon after the flat earth incident. But The Economist has no such qualms: in this week's issue, it wonders... More

6 comments