ad info

 
CNN.com technology > computing
    Editions | myCNN | Video | Audio | Headline News Brief | Feedback  

 

  Search
 
 

 
TECHNOLOGY
TOP STORIES

Consumer group: Online privacy protections fall short

Guide to a wired Super Bowl

Debate opens on making e-commerce law consistent

(MORE)

TOP STORIES

More than 11,000 killed in India quake

Mideast negotiators want to continue talks after Israeli elections

(MORE)

MARKETS
4:30pm ET, 4/16
144.70
8257.60
3.71
1394.72
10.90
879.91
 


WORLD

U.S.

POLITICS

LAW

ENTERTAINMENT

HEALTH

TRAVEL

FOOD

ARTS & STYLE



(MORE HEADLINES)
*
 
CNN Websites
Networks image


Microsoft issues Internet Explorer security patch

Internet Explorer
IDG.net

February 18, 2000
Web posted at: 9:19 a.m. EST (1419 GMT)

(IDG) -- On the eve of the release of its much-delayed Windows 2000, Microsoft Wednesday issued a patch for a security vulnerability in the Internet browser which is bundled with the new operating system.

  MESSAGE BOARD
 

The bug, which Microsoft calls the Image Source Redirect vulnerability, makes it possible for a malicious Web site operator to read certain types of files on the computers of visitors using Internet Explorer (IE) versions 4.0, 4.01, 5.0 and 5.01.

MORE COMPUTING INTELLIGENCE
IDG.net   IDG.net home page
  W2K Day: Let the buying begin
  Download free software fast
  EU opens inquiry into Win2K
  Making the move to Windows 2000
  Reviews & in-depth info at IDG.net
  E-BusinessWorld
  IDG.net's Windows software page
  Questions about computers? Let IDG.net's editors help you
  Subscribe to IDG.net's free daily newsletters
  Search IDG.net in 12 languages
  News Radio
  * Fusion audio primers
  * Computerworld Minute

This means that the iteration of IE which is distributed with Windows 2000, version 5, also is affected by the bug.

When a Web server sends a new page to an IE browser window which comes from a different domain to the one currently being viewed, IE checks the server's permissions on the new page. The vulnerability makes it possible for a Web server to open a browser window to a file stored on the IE user's computer, and then switch to a page in the server's domain, gaining access to the contents of the user's files in the process, Microsoft said in a statement.

Any data which can be seen is only accessible for a short period of time, and the Web site operator would need to know, or guess, the names and locations of files. The operator would also only be able to view file types that can be opened in a browser window, including .txt files, Microsoft said.

Microsoft also came under fire yesterday for a leaked internal memo claiming the operating system has over 63,000 bugs in it.

More information about the vulnerability, including patches, can be found here.



RELATED STORIES:
Another IE 5 security flaw found
October 15, 1999
Microsoft posts IE5 bug fix
October 12, 1999
Zona declares Microsoft winner in browser war
November 10, 1999
Gates officially unveils Windows 2000
February 17, 2000

RELATED IDG.net STORIES:
W2K Day: Let the buying begin
(PC World)
IDC: Windows 2000 a winner for MS
(IDG.net)
Microsoft refutes reports of 63,000 bugs in Windows 2000
(Computerworld)
Windows 2000 launch: Moment of truth arrives
(InfoWorld.com)
EU opens inquiry into Windows 2000
(IDG.net)
Dell says Windows 2000 is ready to roll
(IDG.net)
Windows 2000 only a first step for Microsoft
(Network World)
Making the move to Windows 2000
(InfoWorld.com)

RELATED SITES:
Microsoft
Microsoft's Windows 2000

Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.

 Search   

Back to the top  © 2001 Cable News Network. All Rights Reserved.
Terms under which this service is provided to you.
Read our privacy guidelines.