A problem with Windows 95 and 98

Published: 24 November 1999 y., Wednesday
Microsoft is scrambling to fix numerous Internet security holes in both the Internet Explorer browser and the Windows operating system. Microsoft expects to release a patch Friday for a problem with Windows 95 and 98 that could let a malicious Web site operator or sender of HTML email invade a visitor_s or recipient_s computer. In a buffer overrun situation, the attacker floods a field, in this case the address bar in the browser, with more characters than it can hold. Web addresses or local file addresses that are too long for the address bar can cause Windows to crash and force the characters that didn_t fit into the URL entry field to go into memory, where they may be executed when the computer is restarted. The problem occurs in Windows_ networking software, and an exploit could work with any browser, Microsoft said. Microsoft also released a patch for a bug in the Internet Explorer browser, versions 4.0 and 5.0, that exposes computers to malicious code disguised as common file extensions with suffixes like ".jpg," ".mov" or ".txt" and that get emailed as attachments. The bug takes advantage of an ActiveX control that lets archive files known as "cabinet," or ".cab," files be launched and executed from the user_s machine. Microsoft credited Spanish bug hunter Juan Carlos Garcia Cuartango for discovering the bug, which he originally described as a flaw that made Microsoft_s email management program, Outlook, vulnerable to attack.
Šaltinis: Winfiles
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Italian police shut down hacker rings

Tipped off by American officials, Italian police shut down two rings of hackers who attacked Web sites belonging to the U.S. Army and NASA more »

Yokohama to let residents decide participation in network

Yokohama Mayor Hiroshi Nakada decided Friday to allow residents of the city to choose whether their personal data can be registered in a national resident registry network to be launched Monday by the central government more »

Light speed

An Israeli startup takes on Moore's law--and Texas Instruments more »

Cheap PCs With Lindows Are Well Intentioned but Flawed

Wal-Mart, the most mass-market retailer imaginable, is committing an outrageous form of computing heresy: On its Web site, it's selling Windows-compatible personal computers without Windows more »

Users divided on the meaning of spam

Businesses in the US and UK agree that spam is a problem, but according to MessageLabs many users cannot reach a consensus on its definition more »

search.lt news

search.lt presents newest links more »

The investigation

FORMER FSB OFFICER TESTIFIES ABOUT 1999 APARTMENT-BUILDING BOMBINGS... more »

Gates: Slow going for .Net

Microsoft on Wednesday acknowledged that its .Net plan has been slow to catch on and laid out an agenda to move the software strategy ahead more »

Virus Dials 911

Police Show Up Only to Find Infected WebTVs. more »

AOL blasted for anti-semitic postings

Filters fail to block 'pro-terrorist' messages more »