Version: 2008
  • On BNET: Online porn struggles for profits

August 31, 1999 4:25 PM PDT

Microsoft issues bug repellent

  • Post a comment
Related Stories

Malicious Java code uses IE to access computers

August 30, 1999

Browsers face bug problems

February 24, 1999

Microsoft's inActiveX

February 19, 1998
Microsoft today posted a patch for a security hole in its Internet Explorer 5.0 browser that allows random programs to execute on a user's computer and also can expose those machines to malicious hackers.

As previously reported, the security hole is in the company's popular Web browser on Windows 95 and 98 and allows the execution of arbitrary programs on computers when users visit a Web page or receive Outlook email. It does so by creating, overwriting, and putting content in local files.

The patch is available on Microsoft's Security Advisor Web site. Microsoft said the patch also fixes the same security hole found in IE 4.0.

The problem allows a hacker to take "full control over the user's computer," according to Georgi Guninski, a Bulgarian programmer who discovered the problem. Guninski has reported a number of bugs from various browser makers in the past.

Initially, the security hole was thought to be related to an ActiveX control that ships with IE4 and IE5 and which could have posed a security risk to customers were it used improperly by a malicious hacker, Microsoft said.

The new patch eliminates security vulnerabilities in two ActiveX controls, "Script.typlib" and "Eyedog." These controls are not related, except that both are incorrectly marked as "safe for scripting" and have been pulled from Internet Explorer, Microsoft stated in its patch summary.

ActiveX is component software technology from Microsoft that provides tools for linking desktop applications to the Web. Using a variety of programming tools--including Java, Visual Basic, and C++--developers can create interactive Web content. For instance, ActiveX technology can allow users to view Word and Excel documents directly in a browser.

ActiveX has been criticized in the past for being less secure than other component models.

Beginning next week, Microsoft said it also will post the patch on its Windows Update Web site.

advertisement
Click Here

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (-0.18%) -18.90 10,452.68
S&P 500 (0.03%) 0.38 1,109.24
NASDAQ (0.42%) 9.22 2,185.03
CNET TECH (-0.11%) -1.78 1,593.64
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right