Advertisement
Promo

Office applications Toolkit

IE has another megapatch

John McCormick

Published: 28 May 2002 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Local Information Disclosure Through HTML Object
Attackers must know the name and directory for the file they want to exploit. In addition, the file must contain a specific ASCII character or the attack will fail. Recently patched versions of Outlook and Outlook Express open HTML e-mails in the restricted security zone, which will block this attack as well. Outlook 2002 SP1 with Read As Plain Text enabled for HTML e-mail would also block the attack.

Information Disclosure Vulnerability Cookie Scripts
Microsoft says that an attack would require that the exact name of the cookie be known. The attack requires the user to click on a link. In other words, the attack can't be automated, and the same patches and versions described as being safe in the previous vulnerability (HTML Object CSS) will also be protected from this attack.

Zone Spoofing Through Malformed Web Page
Any attack would require direct NetBIOS connection between the user and the attacker's Web site. A firewall and most ISPs' standard filtering will block the attack. Other vectors of attack using this vulnerability will require a detailed knowledge of the user's system settings, and default settings won't be vulnerable.

Content Disposition variants
Several technical aspects of this attack make it unlikely that it would be successful, including the requirement that the attacker have intimate knowledge of the user's system. This indicates that the attack would probably be successful only if made by an insider, and DNS blocking would foil the attack.

Fix
For the moment, applying the patch supplied with MS02-023 appears to fix all known problems in IE 6.0. Since Microsoft hasn't documented the dialogArguments (Cross-Site Scripting) vulnerability for IE 5.01 and IE 5.5 and, according to GreyMagic, actually patched only a portion of the problem, the current patch doesn't fix this vulnerability in IE 5.01 or IE 5.5. There remains some doubt as to whether IE 6.0 is correctly patched, since the explanation of this vulnerability as given by Microsoft in its security bulletin is in dispute by outside security experts who claim it wasn't properly addressed. The other threats to IE 5.01 and IE 5.5 appear to be corrected by this patch.

Final word
Thanks to GreyMagic for immediately notifying me of problems it discovered with this cumulative patch. I contacted Microsoft for clarification on this matter, but at the time of this writing, I hadn't heard back. I will post any response from Microsoft in the discussion section below.


Have your say instantly in the Tech Update forum.

Find out what's where in the new Tech Update with our Guided Tour.

Let the editors know what you think in the Mailroom.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
145 out of 299 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Video icon

Video

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

Shibley R Shibley R

Copyright in a new light

Monday 28 December 2009, 1:29 PM

7 comments
Shibley R Shibley R

Eigg

Sunday 27 December 2009, 1:04 PM

1 comment

Vista Upgrade Blog

How to Upgrade From Windows Vista to W...

Did you get the news? Microsoft has unzipped its kitty and kept its latest, supposedly the best, offering on display. This is the brand new version of Microsoft operating system, named... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters