All the latest UK technology news, reviews and analysis

More security concerns for Microsoft

by Jonathan Collins in New York

13 Jun 2002

Be the first to comment

  • Tweet this

Fighting a seemingly never-ending battle to secure its internet clientsoftware, Microsoft has released details of "critical" flaws in the security of its Internet Explorer (IE) and Instant Messenger (IM) software.

Not only does the company have no patch for the IE flaw, the patch it had for the IM software replaces an earlier-released one that failed to correct the problem.

Confirming an IE security flaw discovered by Finnish company Online Solutions and announced last week, Microsoft yesterday detailed a way for IE users to protect themselves from attack in the absence of a downloadable patch.

The vulnerability in IE could give a remote user access to a host computer by exploiting a buffer overflow bug in IE's gopher code.

The flaw affects client computers running Internet Explorer 5.01, 5.5 and 6.0, and for internet or intranet servers running Proxy Server 2.0 or ISA Server 2000.

Microsoft noted that older versions of its server products could be vulnerable, but it no longer supports those versions.

In lieu of a patch Microsoft has recommended a work-around that has users changing their browser's internet options settings.

As for the IM security flaws, Microsoft's new patch finishes the job that a patch released on 8 May failed to.

Microsoft's MSN Chat, MSN Messenger and Exchange Instant Messenger all have a flaw that could allow an attacker to run code on target machines via a buffer overflow in ActiveX.

According to Microsoft, the original patch did not stop the affected ActiveX component from being reinstalled on systems in all cases, leaving the potential for patched systems to become vulnerable again. The company released a new set of fixes for all three affected products.

The new security alert, patches and updated versions of the programs can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Software Programmer/Engineer; C#, Winforms, WPF, WF, WCF, SQL

APPLICANTS MUST BE A EU CITIZEN OR HAVE PERMANENT RESIDENCY...

C# Software Developer; C#, winforms, SQL

C# Software Developer/Programmer/engineer; C#, Winforms...

Linux Administrator / Senior Linux Administrator/ Debian Ubuntu

Linux Administrator / Senior Linux Administrator / Debian...

C#, WPF, Silverlight, UI Development, Software Engineers

C#, WPF, Silverlight, UI Development, Software Engineers...

To send to more than one email address, simply separate each address with a comma.