Version: 2008
  • On TechRepublic: 10 cool USB flash drive tricks

October 16, 1998 5:05 PM PDT

Microsoft issues Cuartango patch

  • Post a comment
Related Stories

IE bug opens users' hard drives

October 13, 1998

Microsoft fixes IE security hole

September 8, 1998

Buffer-overflow bug in IE

August 19, 1998

Browser crashes bug Win 98

June 5, 1998

Bug holds up IE 4 users

May 13, 1998

"White-out" bug in IE 4

April 22, 1998

IE 4 for Mac has crypto bug

January 16, 1998

IE 4 URL bug resurfaces

January 14, 1998

IE hole exposes local files

October 17, 1997
Microsoft today issued a patch for a security hole in its Internet Explorer Web browser that exposes users' files to hostile Web site operators and email senders.

The hole, named "Cuartango" after its discoverer, permitted a scripting exploit that allowed someone to swipe files off a victim's hard drive or from their network, either through a maliciously designed Web site they visited or through an HTML-based email received in a program such as Microsoft's Outlook Express or Outlook 98.

For users unable to download the patch, Microsoft recommends the temporary workaround that it offered when the hole surfaced: users can thwart potential attacks by turning off active scripting under Internet Explorer's security zones.

Microsoft Windows product manager Mike Nichols noted that no customers have yet reported actual incidence of a Cuartango exploit. There is, however, a demonstration of it posted on the company's Web site.

Microsoft has had to patch similar file-swiping holes in the past. One surfaced last month, and another last year.

The Cuartango hole affects IE versions 4.01 on Windows 95, Windows NT4, Windows 98 with integrated IE, IE 4.01 on Windows 3.1, and NT 3.51. The problem does not affect Macintosh or Unix versions of IE.

Microsoft refers to the hole as the "untrusted scripted paste" vulnerability, a reference to the way in which the exploit it permits uses scripting to paste a file name into the file upload control--something only the user is supposed to be able to do--and send it to the attacker.

The software giant is warning that all users who have the affected versions of IE on their computers should install the patch--even if they don't use the browser.

Windows 98 users can get the patch through Windows Update. The patch also is posted on Microsoft's Web site.

advertisement

Latest tech news headlines

advertisement

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (2.03%) 203.52 10,226.94
S&P 500 (2.22%) 23.78 1,093.08
NASDAQ (1.97%) 41.62 2,154.06
CNET TECH (2.03%) 31.22 1,569.62
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right