This update eliminates three security vulnerabilities affecting Internet Explorer, and is discussed in Microsoft Security Bulletin MS01-051. Download now to prevent a malicious user from taking advantage of the Zone Spoofing vulnerability, the HTTP Request Encoding vulnerability, or a new variant of the Telnet Invocation vulnerability in Internet Explorer. The first vulnerability involves how Internet Explorer handles URLs that include dotless IP addresses. (Note This vulnerability does not affect Internet Explorer 6.) The second vulnerability involves how Internet Explorer handles URLs that specify third-party sites. The third is a new variant of a vulnerability discussed in Microsoft Security Bulletin MS01-015, affecting how Telnet sessions are invoked via Internet Explorer.
|