Computer Games Forum

Go Back   Computer Games Forum > Tech > Software

Notices

Reply
 
LinkBack Thread Tools
Old 24-08-2002, 13:11   #1 (permalink)
LR
Registered User
 
Join Date: Mar 2000
Location: Alba Iulia
Thumbs up New Security patch For IE 5.1, 5.5 and 6.0 disponible...

http://www.microsoft.com/windows/ie/...ie/default.asp
 
LR is offline    Reply With Quote
Old 25-08-2002, 04:23   #2 (permalink)
Dinutzel's lover
 
Annalyzer's Avatar
 
Join Date: Aug 2000
didn't know... thax for notice.... sper sa fie si ultimul....
__________________
"Doua lucruri sunt nesfârsite în lumea asta: universul si prostia omeneasca... si nu sunt asa de sigur despre univers". (Einstein)

"Sa omori un om e o crima, sa omori o mie e o chestiune de statistica.." (Stalin)
 
Annalyzer is offline    Reply With Quote
Old 25-08-2002, 05:25   #3 (permalink)
Registered User
 
EvilGod's Avatar
 
Join Date: Jun 1999
Location: Pitesti
acum il iau eu ...
Annalyzer u wish !
__________________
Neca eos omnes. Deus suos agnoscet.
 
EvilGod is offline    Send Message via Google Talk to EvilGod Reply With Quote
Old 25-08-2002, 05:31   #4 (permalink)
Dinutzel's lover
 
Annalyzer's Avatar
 
Join Date: Aug 2000
Visam si eu doar.... ce naiba, sunt constient ca IE e un produs Microsoft; nu ma astept la mai mult de la ei...
__________________
"Doua lucruri sunt nesfârsite în lumea asta: universul si prostia omeneasca... si nu sunt asa de sigur despre univers". (Einstein)

"Sa omori un om e o crima, sa omori o mie e o chestiune de statistica.." (Stalin)
 
Annalyzer is offline    Reply With Quote
Old 25-08-2002, 16:43   #5 (permalink)
Registered User
 
Join Date: Apr 2001
Location: Bucuresti
Multumim, LR. Pana una alta e browserul nostru de toate zilele. Pentru cei lenesi, care se intreaba de ce:
"Title: Cumulative Patch for Internet Explorer (Q323759)
Date: 22 August 2002
Software: Internet Explorer
Impact: Six new vulnerabilities, the most serious of which
could enable an attacker to execute commands on a
user's system.
Max Risk: Critical
Bulletin: MS02-047

Microsoft encourages customers to review the Security Bulletin at:
http://www.microsoft.com/technet/se...n/MS02-047.asp.
- ----------------------------------------------------------------------

Issue:
======
This is a cumulative patch that includes the functionality of all previously released patches for IE 5.01, 5.5 and 6.0. In addition, it eliminates the following six newly discovered vulnerabilities:

- A buffer overrun vulnerability affecting the Gopher protocol
handler. This vulnerability was originally discussed in
Microsoft Security Bulletin MS02-027, which provided workaround
instructions while the patch provided here was being completed.

- A buffer overrun vulnerability affecting an ActiveX control used
to display specially formatted text. The control contains a buffer
overrun vulnerability that could enable an attacker to run code
on a user?s system in the context of the user.

- A vulnerability involving how Internet Explorer handles an HTML
directive that displays XML data. By design, the directive
should only allow XML data from the web site itself to be
displayed. However, it does not correctly check for the case
where a referenced XML data source is in fact redirected to a
data source in a different domain. This flaw could enable an
attacker?s web page to open an XML-based files residing a
remote system within a browser window that the site could
read, thereby enabling the attacker to read contents from
websites that users had access to but the attacker was not
able to navigate to.

- A vulnerability involving how Internet Explorer represents the
origin of a file in the File Download Dialogue box. This flaw
could enable an attacker to misrepresent the source of a file
offered for download in an attempt to fool users into
accepting a file download from an untrusted source believing
it to be coming from a trusted source.

- A Cross Domain verification vulnerability that occurs because
of improper domain checking in conjunction with the Object tag.
As a result, the vulnerability could enable a malicious web
site operator to access data across different domains, for
example one in a web site?s domain and the other on the
user?s local file system and then pass information from the
latter to the former. This could enable the web site operator
to read, but not change, any file on the user?s local computer
that could be viewed n a browser window. In addition, this can
also enable an attacker to invoke, but not pass parameters to,
an executable on the local system, much like the
"Local Executable Invocation via Object tag" vulnerability
discussed in MS02-015.

- A newly reported variant of the "Cross-Site Scripting in Local
HTML Resource" vulnerability originally discussed in
Microsoft Security Bulletin MS02-023. Like the original
vulnerability, this variant could enable an attacker to create
a web page that, when opened, would run in the Local Computer
zone, allowing it to run with fewer restrictions than it would
in the Internet Zone.

In addition, the patch sets the Kill Bit on the MSN Chat ActiveX control discussed in Microsoft Security Bulletin MS02-022 as well as the TSAC ActiveX control discussed in Microsoft Security Bulletin MS02-046. This has been done to ensure that vulnerable controls cannot be introduced onto users? systems. Customers who use the MSN Chat control should ensure that they have applied the updated version of the control discussed in MS02-022 and
customers who use the TSAC control should ensure that they
have applied the updated version of the control discussed
in MS02-046".
Il imbunatatim cat putem.
 
Ageamiu is offline    Reply With Quote
Old 25-08-2002, 23:49   #6 (permalink)
Senior Jedi
 
Oby One's Avatar
 
Join Date: Mar 2000
Location: Sierra Wan_Obi
PPfiuuu.....
Use Opera mennnnnn
__________________
A Jedi's strength flows from the force
 
Oby One is offline    Reply With Quote
Advertisment
jocuri prin smsCumpără jocuri prin SMS

Rapid si sigur!
Reply

  Computer Games Forum > Tech > Software

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +2. The time now is 15:46.


This site is copyrighted ©1997 - 2009, Computer Games Online SRL