The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-058: December 2001 Cumulative Patch for IE
Time: 01:26 EST/06:26 GMT | News Source: ActiveWin.com | Posted By: Robert Stein

This is a cumulative patch that, when installed, eliminates all previously discussed security vulnerabilities affecting IE 5.5 and IE 6. In addition, it eliminates three newly discovered vulnerabilities.

  • The first vulnerability involves a flaw in the handling of the Content-Disposition and Content-Type header fields in an HTML stream. These fields, the hosting URL, and the hosted file data determine how a file is handled upon download in Internet Explorer. A security vulnerability exists because, if an attacker altered the HTML header information in a certain way, it could be possible to make IE believe that an executable file was actually a different type of file -- one that it is appropriate to simply open without asking the user for confirmation. This could enable the attacker to create a web page or HTML mail that, when opened, would automatically run an executable on the user's system. This vulnerability affects IE 6.0 only. It does not affect IE 5.5.
  • The second vulnerability is a newly discovered variant of the "Frame Domain Verification" vulnerability discussed in Microsoft Security Bulletin MS01-015. The vulnerability could enable a malicious web site operator to open two browser windows, one in the web site’s domain and the other on the user’s local file system, and to pass information from the latter to the former. This could enable the web site operator to read, but not change, any file on the user’s local computer that could be opened in a browser window. This vulnerabilty affects both IE 5.5 and 6.0.
  • The third vulnerability involves a flaw related to the display of file names in the File Download dialogue box. When a file download is initiated, a dialogue provides the name of the file. However, in some cases, it would be possible for an attacker to misrepresent the name of the file in the dialogue. This could be invoked from a web page or in an HTML email in an attempt to fool users into accepting unsafe file types from a trusted source. This vulnerabilty affects both IE 5.5 and 6.0.
Write Comment
Return to News

  Displaying 701 through 706 of 706
Prev | First
  The time now is 6:02:55 PM ET.
Any comment problems? E-mail us
#701 By 4240821 (45.192.45.37) at 11/12/2025 9:38:35 PM
https://www.pillowfort.social/posts/6446337
https://www.pillowfort.social/posts/6446007
https://www.pillowfort.social/posts/6445911
https://www.pillowfort.social/posts/6445774
https://www.pillowfort.social/posts/6445534
https://www.pillowfort.social/posts/6445342
https://www.pillowfort.social/posts/6445118
https://www.pillowfort.social/posts/6444940
https://www.pillowfort.social/posts/6444780
https://www.pillowfort.social/posts/6444701

#702 By 4240821 (45.192.45.37) at 11/12/2025 10:39:57 PM
https://www.pillowfort.social/posts/6588564
https://www.pillowfort.social/posts/6588059
https://www.pillowfort.social/posts/6587954
https://www.pillowfort.social/posts/6587770
https://www.pillowfort.social/posts/6587581
https://www.pillowfort.social/posts/6587411
https://www.pillowfort.social/posts/6587218
https://www.pillowfort.social/posts/6586979
https://www.pillowfort.social/posts/6586773
https://www.pillowfort.social/posts/6586492

#703 By 4240821 (82.115.4.230) at 11/13/2025 7:03:57 AM
https://sexonly.su/activc1ge5d2e23
https://nsfw.su/activfb3bda4aba
https://smutty.su/activga54fd4ead
https://nsfw.su/activ1fa3gch5he
https://sexonly.top/activ35a55ha2d4
https://sluts.su/activd14h2b1h51
https://nsfw.su/activffefb5ba1a
https://sexonly.su/activf4g3dgaa43
https://smutty.su/activcbbba5hfae
https://smutty.su/activg5544f1135

#704 By 4240821 (45.192.45.37) at 11/13/2025 9:23:53 AM
https://www.pillowfort.social/posts/6844189
https://www.pillowfort.social/posts/6843999
https://www.pillowfort.social/posts/6843879
https://www.pillowfort.social/posts/6843572
https://www.pillowfort.social/posts/6843380
https://www.pillowfort.social/posts/6843232
https://www.pillowfort.social/posts/6843117
https://www.pillowfort.social/posts/6842989
https://www.pillowfort.social/posts/6842846
https://www.pillowfort.social/posts/6842765

#705 By 4240821 (82.115.4.230) at 11/14/2025 10:59:47 AM
https://sexonly.top/activ35gfda3e3a
https://nsfw.su/activaegffe14h4
https://nsfw.su/activ2aaa113hb2
https://sluts.su/activa45515f253
https://nsfw.su/activh1cahfcb5c
https://nsfw.su/activeg52525f21
https://nsfw.su/activdccb5ceh2g
https://sexonly.top/activ4452eb35gc
https://sluts.su/activf114eh4d55
https://smutty.su/activ555ehefabe

#706 By 4240821 (45.192.45.37) at 11/15/2025 1:21:51 AM
https://telegra.ph/Milan-Entella-Ignite-Derby-Drama-as-Last-Gasp-Winner-Seals-It-11-14
https://telegra.ph/Alison-Hammond-Stuns-Fans-with-Unexpected-Talent-The-British-TV-Star-Revealed-as-a-Rising-Comedy-Force-11-14
https://telegra.ph/Global-Shock-as-militaire-operatie-unfolds-unleashing-a-global-outcry-11-14
https://telegra.ph/Rheinmetall-Aktien-Skyrocket-German-Defense-Giant-Sees-Record-Highs-11-14
https://telegra.ph/Dunnes-Stores-Unveils-Stunning-New-Satin-Jacket-11-14
https://telegra.ph/ASFINAGs-Bold-Move-Revolutionizing-Road-Infrastructure-in-Europe-11-14
https://telegra.ph/World-Cup-Qualifiers-Ignite-Passion-and-Unpredictable-Upsets-Across-the-Globe-11-14
https://telegra.ph/John-Aloisis-Last-Minute-Goal-Saves-Australia-in-Dramatic-Euro-2024-Qualifier-11-14
https://telegra.ph/Black-Friday-Blitz-Unbelievable-Deals-Thats-Taking-Over-the-Shopping-World-11-14-3
https://telegra.ph/Snow-Storm-Alert-Winters-Fury-Hits-as-Forecast-Predicts-Heavy-Snowfall-11-14

Write Comment
Return to News
  Displaying 701 through 706 of 706
Prev | First
  The time now is 6:02:55 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *