Microsoft released an unscheduled security patch on Friday designed to fix a trio of serious security problems affecting users of its ubiquitous Internet Explorer Web browser. All three of the security vulnerabilities might be exploited to take control of vulnerable systems, so patching is a necessity.
The flaws involve: an integer overflow involving the way IE processes bitmap files, a memory processing vulnerability in the processing of GIF files and a scripting vulnerability that was the basis of June’s Download.Ject (Scob) attack. All three of these vulnerabilities have been reported to be relatively straightforward to exploit. “Even vigilant users visiting a malicious website, viewing a malformed image, or reading an HTML-rendered email message may be affected,” according to a bulletin from security clearing house US-CERT. No surprise, then, that Redmond gives all three vulnerabilities its dreaded “critical” security classification.
IE versions 5.01, 5.5. and 6 on multiple Windows platforms are affected so it promises to be a busy day for sysadmins everywhere. Early versions of Microsoft’s cumulative patch didn’t apply the final release code for XP customers running the latest version of Windows Update. After correcting this, Microsoft reissued its advisory on Sunday. The latest version of the bulletin is here.
Long-awaited IE patch (finally) arrives @ The Register
» Porn Sites Exploit New Internet Explorer Flaw - Patch Due Oct 10
» Microsoft Issues Patches for ‘Critical’ Flaws in Media Player and Windows
» New Windows Metafile Flaws Emerge
» AV Companies Admit Huge Errors - Symantec, Norton, McAfee AV Flawed
» Microsoft Warns of Windows Image-Handling Flaw
» Microsoft Warns of Critical Windows Flaws - Patch Available Sep 13th
» Microsoft Releases Critical Updates
» Microsoft Issues Security Patches - No IE Fix
» IE Flaw Threat Raised to ‘Extremely Critical’
» Scanner Tool Released To Thwart JPEG Attack
» Security Hole Found In Mozilla Browser
» Secunia Advisory - Microsoft Internet Explorer Vulnerabilities
» Microsoft Warns Of Widespread Windows Flaw - Patch Released
» Microsoft Releases Early Cumulative IE Patch - Phishing Flaw Fixed
» NVIDIA - Nasty File Remover


del.icio.us
Digg
Furl
Netscape
Yahoo! My Web
StumbleUpon
Google Bookmarks
Technorati
BlinkList
Newsvine
ma.gnolia
reddit
Windows Live
Tailrank

