Version: 2008

April 23, 2003 3:25 PM PDT

Microsoft patches holes in IE, Outlook

  • 7 comments
Microsoft once again has welcomed Wednesday with patches for security flaws discovered in its Windows applications.

The software giant warned customers that they should apply updates for both Internet Explorer and Outlook Express to fix critical security vulnerabilities that could let attackers run programs on a victim's PC.

"The No. 1 thing that we want people to walk away with is to install the updates so their machine is protected," said Stephen Toulouse, security program manager for Microsoft's security response center.

Last year, Microsoft began to release advisories midweek due to customer comments indicating such a policy makes it more likely that patches can be applied quickly. Both advisories can be found on the Redmond, Wash., company's Web site.

Internet Explorer 5.01, 5.5 and 6.0 all have four flaws, the worst of which could allow an attacker to take control of a person's computer if a victim were follow links to a Web site or read an HTML (Hypertext Markup Language) e-mail created by an attacker.

A so-called buffer overflow vulnerability, which an attacker can exploit by sending more input to a program than the application expects, could allow the owner of a Web site to run code on the person's computer. Buffer overflows are an old type of vulnerability that still crop up frequently in programs. The flaw occurs in a component of Internet Explorer that delivers Web addresses to the browser from other sources--for instance, if a person clicked on a URL in an e-mail or a Word document.

Two other vulnerabilities allow an attacker to place code on a Web site that would cause the browser to upload a file from a victim's computer. Another flaw affects how the application handles third-party files such as Adobe Systems' portable document format.

The flaw in Outlook Express is in the way that the application handles the encapsulation of HTML in e-mails. A software error in the component allows an attacker to run programs on a victim's computer.

Even Windows users who don't read or send e-mail using Microsoft Outlook Express or browse with Internet Explorer should install the update, the advisories stressed.

The advisories are the software giant's 14th and 15th this year. This is the company's second year of trying to secure its myriad of applications under its Trustworthy Computing Initiative.

Add a Comment (Log in or register) (7 Comments)
  • prev
  • 1
  • next
outlook express
by badisbad October 11, 2005 7:18 AM PDT
most of my work is done over the internet. when a job comes in from my company. i click on to customers e-mail address, it takes me to outlook express. when i've completed my project i click send. a yellow error comes up and states we no longer send e-mail through hot mail. now my project is stuck in outlook express for ever. frankly i'm sick and tired of it . brad
Reply to this comment
This is a test
by tutenstein March 30, 2006 1:01 PM PST
This is a test of a reply to a comment.
Reply to this comment
This is a test of a reply to a comment
by tutenstein March 30, 2006 1:01 PM PST
This is a test of a reply to a comemnt.
This is another test after resin-web install
by tutenstein March 30, 2006 1:48 PM PST
This is another test after resin-web install.
Reply to this comment
A top level comment after sageLibs.xml
by tutenstein March 30, 2006 3:43 PM PST
A top level comment after sageLibs.xml installation.
Reply to this comment
A reply to story after sageLibs install
by tutenstein March 30, 2006 3:43 PM PST
A reply to story after sageLibs install.
Reply to this comment
Reply to comment after sageLibs install
by tutenstein March 30, 2006 3:44 PM PST
Reply to comment after sageLibs install.
(7 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.00%) 0.00 31.00
Dow Jones Industrials (0.13%) 13.60 10,533.70
S&P 500 (0.07%) 0.77 1,127.25
NASDAQ (0.22%) 5.01 2,290.70
CNET TECH (0.21%) 3.54 1,661.46
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right