Internet Explorer file:// Request Zone Bypass Vulnerability

Microsoft Windows operating system, and software for Windows platform, including QuickTime Player and iTunes for Windows. We also discuss topics about Microsoft Corp.

Moderators: Josh, Don_HH2K, Mandrake

Internet Explorer file:// Request Zone Bypass Vulnerability

Postby Edward » Sun 18 May, 2003 8:19 am

Symantec Security Response has an advisory about a zone bypass issue involving Internet Explorer versions 5.5 and 6.0 for various platforms.

http://securityresponse.symantec.com/avcenter/security/Content/7539.html
UserAgent: Opera/7.11 (Windows 98; U) [en]
SillyDog701 Moderator
debian 6 - iceape - iceweasel - icedove - seamonkey
User avatar
Edward
Moderator
Moderator
 
Posts: 3584
Joined: Sun 01 Dec, 2002 7:15 pm

Postby Mandrake » Sun 18 May, 2003 6:29 pm

Brings it up to 11 I think . . . DJGM would know, he loves commenting on IE security (or lack thereof!) :)
UserAgent: Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:1.4b) Gecko/20030517
User avatar
Mandrake
Moderator
Moderator
 
Posts: 4193
Joined: Fri 13 Sep, 2002 6:35 am

Postby Edward » Sun 18 May, 2003 7:20 pm

11?

I thought it was up to 19 or 20 at last glance.
UserAgent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
SillyDog701 Moderator
debian 6 - iceape - iceweasel - icedove - seamonkey
User avatar
Edward
Moderator
Moderator
 
Posts: 3584
Joined: Sun 01 Dec, 2002 7:15 pm

Postby DJGM » Sun 18 May, 2003 8:27 pm

Up until 20th November 2002, there were 32 unpatched security vulnerabilities in versions of IE for Windows.
Microsoft released a cumulative security patch for IE on that day. On 4th Dec 2002, Microsoft released another
cumulative security patch for IE. On 5th February 2003, another cumulative patch for IE was unleashed by MS.
These cumulative security patches are meant to fix several security vulns at a time, but as of 14th Feb 2003,
there were still 13 unpatched vulns in IE. The number of security craters in IE for Windows increased to 14
on 12th March 2003. Microsoft released yet another cumulative security patch for IE on 23rd April 2003.
This latest patch left behind 10 unpatched vulnerabilities! Since then, that number has crept up to 15
unpatched security holes, some of which are holes that had previously been bandaged, but some of
those digital sticking plasters have obviously gotten wet and dropped off! It's getting to the point
that Internet Explorer for Windows is going to urgently need an internet puncture repair kit!
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.4b) Gecko/20030516 Mozilla Firebird/0.6
SeaMonkey = Swiss Army Knife: It's versatile, reliable, and contains useful tools.
Windows Internet Explorer = Old Swiss Cheese: Full of holes, and it stinks!
User avatar
DJGM
diamond member
diamond member
 
Posts: 4572
Joined: Wed 19 Jun, 2002 1:03 pm
Location: Manchester, England, UK


Return to Windows (and Microsoft talk)

Who is online

Registered users: Google [Bot], Yahoo [Bot]