This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

New Iev6 Patch Available...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

MS Bulletin MS04-004
Cumulative Security Update for Internet Explorer (832894)
- http://www.microsoft.com/technet/treeview/…in/MS04-004.asp
"…
Impact of vulnerability: Remote Code Execution
Maximum Severity Rating: Critical…"

(Cumulative update for IEv6 contains 3 patches)

Use WindowsUpdate
-or- download the patch from here:
- http://www.microsoft.com/downloads/details…&displaylang=en

==============================================

FYI…suggest checking with your financial sites PRIOR to installing the patch!

IE Patch Could Disrupt E-Commerce

- http://www.internetnews.com/ec-news/print.php/3306451
January 30, 2004
"Microsoft's planned Internet Explorer modification to fix security holes in the browser could disrupt e-commerce sites that use clear text to authenticate user names and passwords. Lead product manager in Microsoft's Windows division Greg Sullivan told internetnews.com that e-commerce Web sites that send clear text for authentication will return an "invalid syntax error" on Web pages once a user applies the IE patch. That's because the updated browser will remove support for handling user names and passwords in both HTTP and HTTPS URLs. The withdrawn support for clear text authentication effectively provides a workaround for the URL-spoofing flaws that are commonly used by scammers to mask fake sites and trick users into giving up sensitive information including credit card and social security numbers. In advance of the patch release, Microsoft made the unusual move of releasing a knowledge base article to provide details and workarounds for application and Web site developers that still use clear text authentication…"
FYI…

IE patch shuts users out from password-protected sites

- http://www.silicon.com/software/security/p…4655t-40000024c
February 04, 2004
"A critical security patch released this week that fixes vulnerabilities in Internet Explorer has left many users unable to access certain websites and internet resources. Microsoft's latest IE update, which was released outside the monthly patching cycle, stops the company's browser from being used to transfer malicious code to a user's PC and fixes the URL spoofing flaw, but it also stops URLs from being used to access password-protected internet resources, a feature that many companies employ…In addition, the effect of the patch appears to be inconsistent. Some users have found that even after the patch is applied, IE can still be used to access resources with a URL password, contrary to Microsoft's claims."