Microsoft Security Bulletin Ms01-020

As discussed above, this option is not affected by the vulnerability in any way. In addition, it's possible to establish an SSL session with another site, in order to provide convincing proof that the URL is the correct one. What kind of actions could the attachment take if it ran? The vulnerability does not provide any way to force users to the attacker's web site. weblink

Mitigating factors: The user would have to choose to downoad the application before any attempt could be made to exploit the vulnerablity. There is no charge for support calls associated with security patches. It may not be updated when updates to the original are made. For instance, assume that Joe operates a web site.

Remedy: Apply the patch for this vulnerability, as listed in Microsoft Security Bulletin MS01-027. Users must use the Software Update feature of Mac OS X v10.1 to install the "Internet Explorer 5.1 Security Update." More information on Software Update is available at:

It only prevents the checks from being made in certain circumstances. By sending a web request of the type discussed above, she could cause the service to fail, thereby preventing the firewall from passing any web requests, in either direction.

Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. NOTE: This is only the original release of the security bulletin. Second, she could send the email directly to the user.

However, as discussed in the FAQ and in Knowledge Base article Q308411, customers who upgrade to IE 6 on Windows 95, 98, 98SE or ME must select either Typical Install (this To verify the individual files, use the date/time and version information provided in Knowledge Base article Q295279 Caveats: None Localization: This patch can be installed on any language version of ISA If an attacker created an e-mail message containing an executable attachment, and specified that it was one of these MIME types, IE would execute the attachment rather than prompting the user. Microsoft Security Bulletin MS01-053 - Moderate Downloaded Applications Can Execute on Mac IE 5.1 for OS X.

How could an attacker exploit this vulnerability? An attacker would need to host an executable file on a web site, packaged as either a BinHex or MacBinary file, and then entice another See ASP.NET Ajax CDN Terms of Use

Note: Microsoft originally provided a patch for this vulnerability in MS01-020, but it was superseded by the patch released with MS01-027. have a peek at these guys It depends on whether the Web Publishing feature is enabled. Specifically, if CRL checking is selected, IE may not correctly verify the trust status of the root CA, the expiration date for the certificate, or the common name specified in the The web cache helps improve network performance by storing local copies of frequently-requested web content.

No. V1.2 (August 21, 2001): Patch Availability section updated to advise that the patch provided here has been superseded. V1.3 (September 21, 2001): Bulletin updated to discuss need to perform a Full or Typical Install when eliminating this vulnerability via an IE 6 upgrade. check over here Knowledge Base articles can be found on the Microsoft Online Support web site.

Why is IE used to process HTML mails?

Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products. More information on this is available in Knowledge Base article Q308411. To create such an e-mail, an attacker would need to create an e-mail containing an executable attachment, then deliberately edit the MIME headers in the mail to be one of the In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation

What is the Web Proxy service? There are only two differences between the new variants and the previously discussed ones: The specific functions containing the flaw are different. It cannot be exploited without user interaction. Patch availability Download locations for this patch Internet Explorer 5.01 Internet Explorer 5.5 Additional information about this patch Installation platforms: This patch can be installed on systems running Internet Explorer 5.01

