Forum Home
Press F1
 
Thread ID: 17339 2002-04-03 03:06:00 Critical IE patch Guest (0) Press F1
Post ID Timestamp Content User
41519 2002-04-03 03:06:00 Internet Explorer patch: March 28

This is a cumulative patch that includes the functionality of all
previously released patches for IE 5.01, 5.5 and IE 6. In addition, it eliminates the following two newly discovered vulnerabilities:

- A vulnerability in the zone determination function that could allow a script embedded in a cookie to be run in the Local Computer zone. While HTML scripts can be stored in cookies, they should be handled in the same zone as the hosting site associated with them, in most cases the Internet zone. An attacker could place script in a cookie that would be saved
to the user's hard disk. When the cookie was opened by the
site the script would then run in the Local Computer zone, allowing it to run with fewer restrictions than it would otherwise have.

- A vulnerability in the handling of object tags that could allow an attacker to invoke an executable already present on the user's machine. A malicious user could create HTML web page that includes this object tag and cause a local program to run on the victim's machine.

Affected Software:

Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.0

Maximum Severity Rating: Critical

Download for patch:

www.microsoft.com

www.microsoft.com
Guest (0)
41520 2002-04-03 04:04:00 For those with Windows XP you'll find these patchs automatically available to download if you have the auto updater activated.

A very handy XP tool =)
Guest (0)
41521 2002-04-03 04:06:00 Full address here:
www.microsoft.com
Guest (0)
41522 2002-04-03 04:31:00 Ooops, sorry about the bad links. I'll try again:

www.microsoft.com

www.microsoft.com
Guest (0)
1