Version: 2008
  • On MovieTome: The 10 worst movies of 2009 so far!

September 29, 1999 9:10 AM PDT

Microsoft combats another IE 5 bug

  • Post a comment
Related Stories

Microsoft patches Internet Explorer, ActiveX holes

September 29, 1999

Microsoft issues bug repellent

August 31, 1999
Microsoft continues to battle security problems in Internet Explorer 5.0 that make computers vulnerable to attack by malicious Web site operators.

The latest security issue involves an IE 5 feature called "download behavior" that allows a Web page to download files for use in client-side scripting.

By design, a Web site should be able to download files that reside in its domain, preventing client-side code from exposing files on the user's machine. The problem is that a server-side redirect can be used to bypass this restriction, enabling a malicious Web site operator to read an unsuspecting user's local files, according to Microsoft.

As a result of the problem, text files from the user's disk, or local Web server, may be read and then sent to an arbitrary server on the Internet, allowing the user's files to be "stolen," according to Bulgarian programmer Georgi Guninski, who has been credited with discovering numerous security holes in Microsoft and America Online's Web browsers.

"This vulnerability would chiefly affect workstations that are connected to the Internet," Microsoft said in a security alert released yesterday.

The company said it is working on a patch for the problem. "As an immediate measure, customers can prevent the download behavior function from operating by disabling ActiveScripting," according to the security bulletin.

The security hole is the latest in a series of bugs plaguing the software giant's IE browser.

Guninski reported a similar hole in IE in August. Microsoft patched yet another hole in IE's armor around the same time.

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.34%) 34.92 10,344.84
S&P 500 (0.38%) 4.14 1,095.63
NASDAQ (0.29%) 6.16 2,144.60
CNET TECH (0.29%) 4.55 1,574.88
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right