Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft Releases IE Security Update (URL spoofing finally patched)
Microsoft Technet ^ | 02/02/2004 | Microsoft

Posted on 02/02/2004 7:43:06 PM PST by general_re

Microsoft Security Bulletin MS04-004

Cumulative Security Update for Internet Explorer (832894)

Issued: February 2, 2004
Version: 1.0

Summary

Who should read this document: Customers who are using Microsoft® Internet Explorer

Impact of vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Systems administrators should apply the security update immediately.

Security Update Replacement: This update replaces the one that is provided in Microsoft Security Bulletin MS03-048, which is itself a cumulative update.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

* Microsoft Windows NT® Workstation 4.0 Service Pack 6a
* Microsoft Windows NT Server 4.0 Service Pack 6a
* Microsoft Windows NT Server 4.0 Terminal Server Edition, Service Pack 6
* Microsoft Windows 2000 Service Pack 2, Service Pack 3, Service Pack 4
* Microsoft Windows XP, Microsoft Windows XP Service Pack 1
* Microsoft Windows XP 64-Bit Edition, Microsoft Windows XP 64-Bit Edition Service Pack 1
* Microsoft Windows XP 64-Bit Edition Version 2003
* Microsoft Windows Server® 2003
* Microsoft Windows Server 2003, 64-Bit Edition

(Excerpt) Read more at microsoft.com ...


TOPICS: Business/Economy; Miscellaneous; News/Current Events; Technical
KEYWORDS: ie; lowqualitycrap; microsoft; patch; security; spoof; url; windows
Navigation: use the links below to view more comments.
first 1-2021 next last
Patch already available via Windows Update...
1 posted on 02/02/2004 7:43:07 PM PST by general_re
[ Post Reply | Private Reply | View Replies]

To: general_re
Oh cripes..not again.

2 posted on 02/02/2004 7:44:26 PM PST by Neets (Complainers change their complaints, but they never reduce the amount of time spent in complaining.~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Neets
Actually, this is a good thing - this bug has been known for some time, but now the fix is finally available. I strongly suggest that people using IE install the patch as soon as possible...
3 posted on 02/02/2004 7:45:49 PM PST by general_re (Remember that what's inside of you doesn't matter because nobody can see it.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Neets
Better apply it -- now ALL the hackers know about it.
4 posted on 02/02/2004 7:46:15 PM PST by old-ager
[ Post Reply | Private Reply | To 2 | View Replies]

To: general_re
No, I know it's a good thing...

...IT guy won't be happy to hear this tho...we have over 100 Lab computers that will need to be updated.
5 posted on 02/02/2004 7:46:47 PM PST by Neets (Complainers change their complaints, but they never reduce the amount of time spent in complaining.~)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Neets
Ah. Well, at least you have a month to work it out, since I think that's it until March, patchwise ;)
6 posted on 02/02/2004 7:48:13 PM PST by general_re (Remember that what's inside of you doesn't matter because nobody can see it.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: general_re
Mercifully, the number of Windows patches has declined... two years ago it seemed as if Windows needed a patch every other week. Today you can go months before a critical upgrade is made available. I consider that progress.
7 posted on 02/02/2004 7:48:50 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
Good. We've been waiting for this one. Thanks for the heads up.
8 posted on 02/02/2004 7:51:48 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Neets
Your IT guy needs to install a Software Update Server (SUS), which is available free from Microsoft. The SUS replaces the Automatic update feature on your Domain PC's with a SUS client. When updates are downloaded and approved on the SUS, they are automatically deployed to the client PC's.

The 100+ machine network I administer will be updating itself while I sleep. Life is good...
9 posted on 02/02/2004 7:56:36 PM PST by Sledge
[ Post Reply | Private Reply | To 5 | View Replies]

To: general_re
I at this second, just finished downloading the thing, I'll install after I go offline.

it was an automatic update, I didn't even notice until it was 97% finished.

10 posted on 02/02/2004 7:59:39 PM PST by GeronL (www.ArmorforCongress.com ............... Support a FReeper for Congress)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Neets
Automatic Update.... its there for a reason... =o)
11 posted on 02/02/2004 8:00:35 PM PST by GeronL (www.ArmorforCongress.com ............... Support a FReeper for Congress)
[ Post Reply | Private Reply | To 5 | View Replies]

To: general_re
Oh, puhleeze.

Buffer Overflow City.

Microsoft is to security what the Clintons are to morality.

12 posted on 02/02/2004 8:01:39 PM PST by George Smiley (Is the RKBA still a right if you have to get the government's permission before you can exercise it?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: George Smiley
Thanks for the bump.
13 posted on 02/02/2004 8:08:20 PM PST by general_re (Remember that what's inside of you doesn't matter because nobody can see it.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: old-ager
Better apply it -- now ALL the hackers know about it.

This has been known for a very long time, to our surprise, MS finally got around to fixing it. When was it they were trying to say they fix security flaws faster than OSS?

14 posted on 02/02/2004 8:19:59 PM PST by antiRepublicrat
[ Post Reply | Private Reply | To 4 | View Replies]

To: general_re
How long did it take them to fix this HUGE hole?

Over a month? or has it been two months now?

How many millions of dollars have been lost to scams by this flaw?

Or WAS it a flaw? Could it have been a government order to attempt to spoof us?
15 posted on 02/02/2004 9:15:46 PM PST by steplock (www.FOCUS.GOHOTSPRINGS.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
Good. It seems that this patch has also corrected the problem with the vertical scrollbar in IE, which an earlier patch had apparently created.
16 posted on 02/02/2004 9:34:54 PM PST by Ouachita
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re
Duplicate thread:

http://www.freerepublic.com/focus/f-chat/1070325/posts

I really don't mind, though -- I just wanted to link the two together.

You probably didn't see it because I also posted it to "Front Page News".

17 posted on 02/02/2004 10:08:13 PM PST by justlurking
[ Post Reply | Private Reply | To 1 | View Replies]

To: justlurking
Ah, I missed the magic combination of words that would reveal it when I searched - sorry ;)
18 posted on 02/02/2004 10:11:27 PM PST by general_re (Remember that what's inside of you doesn't matter because nobody can see it.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Ouachita
Thank you. THANK YOU! The double scroll problem is finally fixed. This, folks, is the problem whereby you click on the scrollbar and it goes down TWO screens instead of the expected one screen that popped up after a previous update. It now works properly again.

19 posted on 02/02/2004 10:11:47 PM PST by Rightone
[ Post Reply | Private Reply | To 16 | View Replies]

To: Rightone
http://www.mozilla.org/products/firebird/

That will fix your problem! ;)


20 posted on 02/03/2004 6:02:58 AM PST by adam_az (Be vewy vewy qwiet, I'm hunting weftists.)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson