Microsoft patches IE, Windows.
Published:
24 November 1999 y., Wednesday
Microsoft is scrambling to fix numerous Internet security holes in both the Internet Explorer browser and the Windows operating system. Microsoft expects to release a patch Friday for a problem
with Windows 95 and 98 that could let a malicious Web site operator or sender of HTML email invade a visitor_s or recipient_s computer. In a buffer overrun situation, the attacker floods a field, in this case the address bar in the browser, with more characters than it can hold. Web addresses or local file
addresses that are too long for the address bar can cause Windows to crash and force the characters that didn_t fit into the URL entry field to go into memory, where they may be executed when the computer is restarted. The problem occurs in Windows_ networking software, and an exploit could work with any browser, Microsoft said. Microsoft also released a patch for a bug in the Internet Explorer browser, versions 4.0 and 5.0, that exposes computers to malicious code disguised as common file extensions with suffixes like ".jpg," ".mov" or ".txt" and that get emailed as attachments. The bug takes advantage of an ActiveX control that lets archive files known as "cabinet," or ".cab," files be launched and executed from the user_s machine. Microsoft credited Spanish bug hunter Juan Carlos Garcia Cuartango for discovering the bug, which he originally described as a flaw that made Microsoft_s email management program, Outlook, vulnerable to attack.
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.
The most popular articles
Software company announced new structure_ of it_s business.
more »
ParallelGraphics Web3D project tracks MIR's Final Journey Back
more »
Norwegians to Implement Largest-Ever E-Business Project
more »
Orbitz - the airline industry's embattled Internet-ticketing project - will strengthen rather than stifle competition in the travel industry, according to a new report commissioned by Orbitz.
more »
A World Wide Web of Organized Crime An Eastern European ring may have lifted over a million credit-card numbers from the Net.
more »
Software can now produce encrypted worms
more »
After opening its quarterly forum to public input, the International Corporation for Assigned Names and Numbers (ICANN) has been criticized for protecting the monopoly of US domain name registrar VeriSign
more »
For the past year, Eastern European-based hackers have been systematically exploiting known Windows NT vulnerabilities to steal customer data, according to reports from the FBI and SANS Institute.
more »
Despite a slow start, the Internet appliance market is poised to grow dramatically, with shipments of more than 174 million units expected by 2006
more »
search.lt presents newest links
more »
An Internet startup that plans to create its own top-level domain names is likely to cause bigger trouble for Web surfers than for the Internet Corporation for Assigned Names and Numbers, ICANN officials say.
more »