The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-015: 28 March 2002 Cumulative Patch for Internet Explorer
Time: 19:30 EST/00:30 GMT | News Source: Microsoft TechNet Security | Posted By: Julien Jay

This is a cumulative patch that includes the functionality of all previously released patches for IE 5.01, 5.5 and IE 6. In addition, it eliminates the following two newly discovered vulnerabilities:

  • A vulnerability in the zone determination function that could allow a script embedded in a cookie to be run in the Local Computer zone. While HTML scripts can be stored in cookies, they should be handled in the same zone as the hosting site associated with them, in most cases the Internet zone. An attacker could place script in a cookie that would be saved to the user’s hard disk. When the cookie was opened by the site the script would then run in the Local Computer zone, allowing it to run with fewer restrictions than it would otherwise have.
  • A vulnerability in the handling of object tags that could allow an attacker to invoke an executable already present on the user’s machine. A malicious user could create HTML web page that includes this object tag and cause a local program to run on the victim’s machine.

Patch availability:

http://www.microsoft.com/windows/ie/downloads/critical/Q319182/default.asp

Write Comment
Return to News

  Displaying 301 through 301 of 301
Prev | First
  The time now is 8:46:50 PM ET.
Any comment problems? E-mail us
#301 By 4240821 (62.76.153.72) at 11/24/2024 10:52:12 AM
https://justpaste.me/BdKG5
https://justpaste.me/BhWs3
https://justpaste.me/Bruf1
https://justpaste.me/CTA32
https://justpaste.me/CTWh1
https://justpaste.me/CL9j2
https://justpaste.me/Bp5B
https://justpaste.me/CIFX2
https://justpaste.me/Bgex5
https://justpaste.me/CCmG2

Write Comment
Return to News
  Displaying 301 through 301 of 301
Prev | First
  The time now is 8:46:50 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *