Update Available For MSHTML Security Issues In Internet Explorer
ID: Q226325
|
The information in this article applies to:
-
Microsoft Internet Explorer versions 4.0, 4.01 Service Pack 2, 5 for Windows 98
-
Microsoft Internet Explorer versions 4.0, 4.01, 4.01 Service Pack 1, 4.01 Service Pack 2, 5 for Windows 95
-
Microsoft Internet Explorer versions 4.0, 4.01, 4.01 Service Pack 1, 4.01 Service Pack 2, 5 for Windows NT 4.0
-
Microsoft Windows 98
SUMMARY
Microsoft has released an update to Internet Explorer that addresses three security vulnerabilities in Internet Explorer's parsing engine, Mshtml.dll. Additional information about this issue is available from the
following Microsoft Web sites:
Updates are available for the following products:
- Microsoft Internet Explorer 4.0, 4.01 for Windows 95 and Windows NT 4.0 (x86 and Alpha)
- Microsoft Windows 98
- Microsoft Internet Explorer 5 for Windows 95, Windows 98, and Windows NT 4.0 (x86 and Alpha)
This update addresses the following three vulnerabilities in Internet Explorer:
- The IMG SRC tag can point to items other than images, allowing someone to obtain access to information about local files through Internet Explorer's object model.
- A new variant of the "cross-frame" vulnerability that was previously addressed. For additional information about this issue, please see the following article(s) in the Microsoft Knowledge Base:
Q168485 Update Available for Cross-Frame Security Issue
- A new variant of the previously-addressed "untrusted scripted paste" vulnerability. For additional information about this issue, please see the following
article(s) in the Microsoft Knowledge Base:
Q169245 Update Available for "Untrusted Scripted Paste" Issue
Additionally, This update also fixes the "Untrusted Scripted Paste", "Cross Frame Navigate", and "Frame Spoof" security issues in Microsoft Internet Explorer running on Windows operating systems. For additional information about these issues, please see the following article(s) in the Microsoft Knowledge Base:
Q169245 Update Available for "Untrusted Scripted Paste" Issue
Q168485 Update Available for Cross-Frame Security Issue
Q167614 Update Available For "Frame Spoof" Security Issue
MORE INFORMATION
Update Information by Product:
NOTE: If you are using Internet Explorer 4.0 or 4.01, you must install
Internet Explorer 4.01 Service Pack 1 or 2 in order to apply this update. You can install Internet Explorer 4.01 with Service Pack 2 from the following Microsoft Web site:
http://www.microsoft.com/windows/ie/download
Microsoft Internet Explorer 4.0, 4.01, and 4.01 with Service Pack 1 or 2 for Windows 95
Update File Name: mshtml4.exe
Availability: http://www.microsoft.com/windows/ie/security
Updated File Name |
Size (bytes) |
Date |
Version |
Mshtml.dll |
2,422,544 |
4-13-99 |
4.72.3616.1301 |
Mshtmlwb.dll |
55,872 |
4-14-99 |
4.72.3616.1400 |
Microsoft Internet Explorer 4.0, 4.01, and 4.01 with Service Pack 1 or 2 for Windows NT 4.0 (x86)
Update File Name: mshtml4.exe
Availability: http://www.microsoft.com/windows/ie/security
Updated File Name |
Size (bytes) |
Date |
Version |
Mshtml.dll |
2,422,544 |
4-13-99 |
4.72.3616.1301 |
Mshtmlwb.dll |
55,872 |
4-14-99 |
4.72.3616.1400 |
Microsoft Internet Explorer 4.0, 4.01, and 4.01 with Service Pack 1 or 2 for Windows NT 4.0 (Alpha)
Update File Name: mshtml4ax.exe
Availability: http://www.microsoft.com/windows/ie/security
Updated File Name |
Size (bytes) |
Date |
Version |
Mshtml.dll |
3,951,888 |
4-14-99 |
4.72.3616.1400 |
Mshtmlwb.dll |
113,424 |
4-15-99 |
4.72.3616.1400 |
Windows 98
Update File Name: mshtml4.exe
Availability: http://www.microsoft.com/windows/ie/security
Updated File Name |
Size (bytes) |
Date |
Version |
Mshtml.dll |
2,422,544 |
4-13-99 |
4.72.3616.1301 |
Mshtmlwb.dll |
55,872 |
4-14-99 |
4.72.3616.1400 |
Microsoft Internet Explorer 5 for Windows 95, Windows 98, or Windows NT 4.0 (x86)
Update File Name: mshtml5.exe
Availability: http://www.microsoft.com/windows/ie/security
Updated File Name |
Size (bytes) |
Date |
Version |
Mshtml.dll |
2,359,568 |
4-14-99 |
5.0.2614.3401 |
Microsoft Internet Explorer 5 for Windows NT 4.0 (Alpha)
Update File Name: mshtml5ax.exe
Availability: http://www.microsoft.com/windows/ie/security
Updated File Name |
Size (bytes) |
Date |
Version |
Mshtml.dll |
4,982,544 |
4-14-99 |
5.0.2614.3401 |
Additional query words:
2.0 2.00 4.00 5.0 5.00
Keywords : kbfile msiew95 msient win98 msiew98
Version : WINDOWS:4.0,4.01,4.01 Service Pack 1,4.01 Service Pack 2,5
Platform : WINDOWS
Issue type : kbinfo
Last Reviewed: April 20, 1999