Home Schools Links Virus List Add a School Change a Link Dead Link
Link to us Financial Aid Free E-mail Guestbook Cool Links Tell A Friend
NextCard Visa If your School has a Schools Alumni Page let us know Solve your computer needs at eBay


Internet Explorer 5
Bug

 
Tell A Friend
about this
Page
Tell me when
this page
is updated
Link to us
Our Sponsor

Microsoft Security Bulletin (MS99-040)

Patch Available for "Download Behavior" Vulnerability
Originally Posted: September 28, 1999
Updated: October 08, 1999

Summary
On September 28, 1999, Microsoft released the original version of this bulletin, in order to  provide a workaround for a security vulnerability in Microsoft(r) Internet Explorer 5 that could  allow a malicious web site operator to read files on the computer of a person who visited the site. Microsoft has completed a patch that completely eliminates the vulnerability, and has  re-released this bulletin in order to advise customers of its availability.

Frequently asked questions regarding this vulnerability can be found at:
http://www.microsoft.com/security/bulletins/MS99-040faq.asp.

Issue
IE 5 includes a feature called "download behavior" that allows web page authors to download files  for use in client-side script. By design, a web site should only be able to download files that reside in its domain; this prevents client-side code from exposing files on the user's machine or local intranet to the web site. However, a server-side redirect can be used to bypass this  restriction, thereby enabling a malicious web site operator to read files on the user's machine  or the user's local intranet. This vulnerability would chiefly affect workstations that are  connected to the Internet.

Affected Software Versions
Microsoft Internet Explorer 5

Patch Availability
The patch is available for download at either of the following
locations:
http://windowsupdate.microsoft.com
or
http://www.microsoft.com/msdownload/iebuild/dlbhav/en/dlbhav.htm

More Information
Please see the following references for more information related to this issue.
Microsoft Security Bulletin MS99-040: Frequently Asked Questions,
http://www.microsoft.com/security/bulletins/ms99-040faq.asp.

Microsoft Knowledge Base (KB) article Q242542, "Download Behavior" Vulnerability in Internet Explorer 5:
http://support.microsoft.com/support/kb/articles/Q242/5/42.asp.

(Note: It may take 24 hours from the original posting of this bulletin for this KB article to be visible.)
Microsoft Security Advisor web site:
http://www.microsoft.com/security/default.asp.

Obtaining Support on this Issue
Information on contacting Microsoft Technical Support is available at:
http://support.microsoft.com/support/contact/default.asp.

Acknowledgments
Microsoft acknowledges Georgi Guninski for bringing this issue to our attention.

Revisions
September 28, 1999: Bulletin Created.
October 08, 1999: Bulletin updated to announce availability of patch.


THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE
BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR
LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.

(c) 1999 Microsoft Corporation. All rights reserved. Terms of Use.

 


 

[an error occurred while processing this directive]

Gator fills out forms and remembers passwords!


Howdy!!!
Welcome to the McCann's PooR Farm
I'm not with any school or schools,
Just a disable grandpa with 17 grand kids, 1 Great grand Kid
 
Sorry! about all of the adds, Our Cost just keeping going up.
Please click on one of them and help us out. or
Send $1.00 U.S. to:
McCann's Poor Farm
20509 Lawrence 2207
Aurora, Mo. 65605-7275
Thank You,
Junior McCann
Webmaster
and the GrandKids
 
See what the experts have to say about the McCann's Poor Farm Web Page
 
Legal Disclaimer - We Are in no way connected with any School and or Companies linked to this page. Links are provided as a courtesy only.

Where Visitors Come From:

Argentina, Australia, Austria, Belarus, Belgium, Bermuda, Brazil, Brunei Darussalam, Bulgaria, Canada, Chile, Columbia, Costa Rica, Croatia, Croatia/Hrvatska, Czech Republic, Denmark, Dominican Republic, Ecuador, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Jordan, Korea, Korea, Republic of, Latvia, Lebanon, Lithuania, Luxembourg, Macedonia, Malaysia, Mexico, Moldova, Netherlands, New Calendonia, New Zealand, Norway, Old style Arpanet, Papua New Guinea, Peru, Philippines, Poland, Portugal, Romania, Russian Federation, Saudi Arabia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Thailand, Turkey, Uganda, Ukraine, United Arab Emirates, United Kingdom, United States, Uruguay, USA Government, USA Military, Viet Nam
Tell A Friend
about this Page
Tell me when this page
is updated

Click Here!


Home Schools Links Virus List Add a School Change a Link Dead Link
Scholarships Financial Aid Free E-mail Guestbook Cool Links Tell A Friend
Put a Link on your Web Page

- Legal Disclaimer -
This Website Is For Your Entertainment Purposes Only!
We Are in no way connected with
any School and or Companies linked to this page.
Links are provided as a courtesy only.
 
http://www.poor-farm.com/
webmaster@poor-farm.com
McCann's PooR Farm
Aurora, Mo. 65605
© 2001