![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
#1 |
Ironworks Atomic Moderator
![]() Join Date: January 7, 2001
Location: Virginia, U.S.A.
Age: 58
Posts: 9,005
|
I think we should begin to call it Microsoft Security Patch of the Week club eh? Here is the latest info, everyone should download this if you haven't already:
Microsoft Security Bulletin MS01-058 13 December 2001 Cumulative Patch for IE Originally posted: December 13, 2001 Summary Who should read this bulletin: Customers using Microsoft® Internet Explorer. Impact of vulnerability: Run code of attacker’s choice. Maximum Severity Rating: Critical Recommendation: Customers using IE should install the patch immediately. Affected Software: Microsoft Internet Explorer 5.5 Microsoft Internet Explorer 6.0 This is a cumulative patch that, when installed, eliminates all previously discussed security vulnerabilities affecting IE 5.5 and IE 6. In addition, it eliminates three newly discovered vulnerabilities. The first vulnerability involves a flaw in the handling of the Content-Disposition and Content-Type header fields in an HTML stream. These fields, the hosting URL, and the hosted file data determine how a file is handled upon download in Internet Explorer. A security vulnerability exists because, if an attacker altered the HTML header information in a certain way, it could be possible to make IE believe that an executable file was actually a different type of file -- one that it is appropriate to simply open without asking the user for confirmation. This could enable the attacker to create a web page or HTML mail that, when opened, would automatically run an executable on the user's system. This vulnerability affects IE 6.0 only. It does not affect IE 5.5. The second vulnerability is a newly discovered variant of the "Frame Domain Verification" vulnerability discussed in Microsoft Security Bulletin MS01-015. The vulnerability could enable a malicious web site operator to open two browser windows, one in the web site’s domain and the other on the user’s local file system, and to pass information from the latter to the former. This could enable the web site operator to read, but not change, any file on the user’s local computer that could be opened in a browser window. This vulnerabilty affects both IE 5.5 and 6.0. The third vulnerability involves a flaw related to the display of file names in the File Download dialogue box. When a file download is initiated, a dialogue provides the name of the file. However, in some cases, it would be possible for an attacker to misrepresent the name of the file in the dialogue. This could be invoked from a web page or in an HTML email in an attempt to fool users into accepting unsafe file types from a trusted source. This vulnerabilty affects both IE 5.5 and 6.0. To download & install: http://www.microsoft.com/windows/ie/...5/download.asp |
![]() |
![]() |
#2 |
Zartan
![]() Join Date: March 11, 2001
Location: North Carolina USA
Age: 58
Posts: 5,177
|
Thanks for the heads up!
__________________
[img]\"http://home.carolina.rr.com/orthanc/pics/Spinning%20Hammer%20Sig%20Pic.gif\" alt=\" - \" /> |
![]() |
![]() |
#3 |
Guest
Posts: n/a
|
LadyZ,
Thank you very much for keeping us informed! |
![]() |
#4 |
Lord Soth
![]() Join Date: March 5, 2001
Location: Southern California
Posts: 1,948
|
Lady Z, do you work in IS? I notice that you have these virus and security updates kinda frequently.
__________________
\"The object of war is not to die for your country but to make the other bastard die for his.\"<br />-General George Patton (1885-1945)<br /> ![]() |
![]() |
![]() |
#5 |
Ironworks Atomic Moderator
![]() Join Date: January 7, 2001
Location: Virginia, U.S.A.
Age: 58
Posts: 9,005
|
Nah, I just like to keep my eyes and ears open on these things, and check Microsoft often for latest patches.
![]() |
![]() |
![]() |
#6 |
Harper
![]() Join Date: October 6, 2001
Location: Iceland
Posts: 4,706
|
Urgg, stupid Microsoft, can't they get ANYTHING right?
Amazing day it will be when the headlines will read MICROSOFT RELEASES A SOFTWARE THAT IS ACTUALLY FINISHED [Jorath grumbles some more and starts downloading...] [img]smile.gif[/img] |
![]() |
![]() |
#7 |
Avatar
![]() ![]() ![]() ![]() Join Date: November 12, 2001
Location: Netherlands
Age: 56
Posts: 522
|
Thanks LadyZ for the tip,But i had to install the latest version of IE first,so that's done now too [img]smile.gif[/img]
__________________
![]() |
![]() |
![]() |
#8 |
Red Dragon
![]() Join Date: March 1, 2001
Location: Long Beach, CA. USA
Age: 68
Posts: 1,589
|
Yep, thanx LadyZekke. I get automatic Microsoft update/download notices on my system, so I have it. [img]smile.gif[/img]
|
![]() |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Some Qs on the CEP, Undermountain and the latest patch | Memnoch | NWN Mod: Escape from Undermountain | 5 | 04-24-2005 08:12 AM |
Microsoft Internet Explorer Security Issues | Knightscape | General Conversation Archives (11/2000 - 01/2005) | 0 | 06-28-2004 02:09 AM |
Beware latest virus masquerading as Microsoft Client | Memnoch | General Conversation Archives (11/2000 - 01/2005) | 7 | 09-29-2003 08:54 PM |
latest patch | Fallen | Neverwinter Nights 1 & 2 Also SoU & HotU Forum | 3 | 10-08-2002 07:01 AM |
ALERT: Microsoft Explorer v5.01 through v6.00 Critical Security Patch | Ziroc | General Conversation Archives (11/2000 - 01/2005) | 13 | 02-16-2002 04:42 PM |