Microsoft offers patch for six IE flaws
Computerworld -
Microsoft Corp. has released a patch to fix six vulnerabilities, three of which are ranked "critical," that have shown up in its Internet Explorer (IE) browser software.
According to the company's bulletin, the flaws can allow attackers to access information on victim's machines and to launch attacks using cross-site scripting.
The bulletin says that if an attacker hosts a Web site or sends an HTML-based e-mail message and a victim either views the site or clicks on an infected Web site address, the attacker can then place a malicious program on the victim's machine.
Other vulnerabilities would allow an attacker to do the following:
- Read but not change data on a target computer if the attacker knows the location of specific files.
- Read cookies on another person's computer, provided the attacker knows the exact name of the cookies targeted.
- Change the security settings on a victim's browser.
- Trick a victim's browser into accepting malformed files, provided the attacker knows the victim has a vulnerable application running on his machine.
- Send HTML e-mail to automatically open new windows or to launch the download of an executable file.
In addition to tackling the six flaws, the patch will eliminate all previously reported vulnerabilities with IE 5.01, 5.5 and 6.0, Microsoft said.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
