Advertisement
Promo

Office applications Toolkit

IE has another megapatch

John McCormick

Published: 28 May 2002 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Applicability
Microsoft Internet Explorer releases 5.01, 5.5, and 6.0 are affected by these threats. Microsoft no longer supports earlier versions of IE, although they could be affected by these flaws.

Risk level -- critical
Microsoft rates a number of the covered vulnerabilities as critical and recommends that any users of IE 5, IE 5.5, or IE 6 apply this patch immediately.

Cross-Site Scripting in Local HTML Resource is critical for IE 6.0 clients and moderate for servers. According to Microsoft, this poses no threat to IE 5.01 and IE 5.5, but if GreyMagic is correct -- and as far as I can determine, it is -- IE 5.01 occasionally and IE 5.5 always remain vulnerable to this threat even after this patch.

The Local Information Disclosure Through HTML Object threat affects IE 5.01, IE 5.5, and IE 6.0 and is critical for client systems and moderate for servers.

The Information Disclosure Vulnerability Cookie Scripts threat affects IE 5.5 and IE 6.0 and is critical for client systems and moderate for servers. According to Microsoft, IE 5.01 is not vulnerable.

The Zone Spoofing Through Malformed Web Page flaw is low for all. The Content Disposition variants are moderate for IE 5.01 and 6.0 servers and clients and pose no risk for IE 5.5 client or server.

Mitigating factors
Cross-Site Scripting in Local HTML Resource
Microsoft says that there is no way to automate this attack because it requires the user to click on a hyperlink. However, according to GreyMagic, "This is simply wrong; the user doesn't have to click anything for this issue to be exploited. It can run automatically." Microsoft also indicated that correctly updated and patched versions of Outlook, Outlook Express, and Outlook 2002 SP1 now open all HTML code in the Restricted Sites Zone, which would block this attack.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
145 out of 299 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:













Video icon

Video

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:40 PM

3 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:38 PM

3 comments
Shibley R Shibley R

Question!

Friday 25 December 2009, 11:09 AM

3 comments

Vista Upgrade Blog

How to Upgrade From Windows Vista to W...

Did you get the news? Microsoft has unzipped its kitty and kept its latest, supposedly the best, offering on display. This is the brand new version of Microsoft operating system, named... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters