13 Jun 2002
Fighting a seemingly never-ending battle to secure its internet clientsoftware, Microsoft has released details of "critical" flaws in the security of its Internet Explorer (IE) and Instant Messenger (IM) software.
Not only does the company have no patch for the IE flaw, the patch it had for the IM software replaces an earlier-released one that failed to correct the problem.
Confirming an IE security flaw discovered by Finnish company Online Solutions and announced last week, Microsoft yesterday detailed a way for IE users to protect themselves from attack in the absence of a downloadable patch.
The vulnerability in IE could give a remote user access to a host computer by exploiting a buffer overflow bug in IE's gopher code.
The flaw affects client computers running Internet Explorer 5.01, 5.5 and 6.0, and for internet or intranet servers running Proxy Server 2.0 or ISA Server 2000.
Microsoft noted that older versions of its server products could be vulnerable, but it no longer supports those versions.
In lieu of a patch Microsoft has recommended a work-around that has users changing their browser's internet options settings.
As for the IM security flaws, Microsoft's new patch finishes the job that a patch released on 8 May failed to.
Microsoft's MSN Chat, MSN Messenger and Exchange Instant Messenger all have a flaw that could allow an attacker to run code on target machines via a buffer overflow in ActiveX.
According to Microsoft, the original patch did not stop the affected ActiveX component from being reinstalled on systems in all cases, leaving the potential for patched systems to become vulnerable again. The company released a new set of fixes for all three affected products.
The new security alert, patches and updated versions of the programs can be found here.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
APPLICANTS MUST BE A EU CITIZEN OR HAVE PERMANENT RESIDENCY...
C# Software Developer/Programmer/engineer; C#, Winforms...
Linux Administrator / Senior Linux Administrator / Debian...
C#, WPF, Silverlight, UI Development, Software Engineers...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?