Security Home
>
Internet Explorer
Cumulative Patch for Internet Explorer New
Microsoft has released a cumulative patch that includes the functionality of all previously released patches for Internet Explorer 5.01, 5.5 and 6.0 and also resolves 4 new security vulnerabilities.
Issue
This patch eliminates the following four newly discovered vulnerabilities:
A buffer overrun vulnerability in URLMON.DLL that occurs because Internet Explorer does not correctly check the parameters of information being received from a web server. It could be possible for an attacker to exploit this vulnerability to run arbitrary code on a user's system. A user simply visiting an attacker’s website could allow the attacker to exploit the vulnerability without any other user action.
A vulnerability in the Internet Explorer file upload control that allows input from a script to be passed to the upload control. This vulnerability could allow an attacker to supply a file name to the file upload control and automatically upload a file from the user’s system to a web server.
A flaw in the way Internet Explorer handles the rendering of third party files. The vulnerability results because the Internet Explorer method for rendering third party file types does not properly check parameters passed to it. An attacker could create a specially formed URL that would inject script during the rendering of a third party file format and cause the script to execute in the security context of the user.
A flaw in the way modal dialogs are treated by Internet Explorer that occurs because an input parameter is not properly checked. This flaw could allow an attacker to use an injected script to provide access to files stored on a user’s computer. Although a user who visited the attacker’s website could allow the attacker to exploit the vulnerability without any other user action, an attacker would have no way to force the user to visit the website.
Affected Products
- Microsoft Internet Explorer 5.01
- Microsoft Internet Explorer 5.5
- Microsoft Internet Explorer 6.0
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: April 23, 2003
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<