Feeds

Serious Outlook hole patched

ActiveX threats, memory leaks, cross-site scripting and more

  • alert
  • submit to reddit

Intelligent flash storage arrays

MS Bug Roundup MS has patched a serious vulnerability in Outlook 2002 by which an attacker could take over one's machine. At issue is an ActiveX feature, the Outlook View Control, which enables mail folders to be viewed via Web pages. In Outlook 2K the flaw doesn't give up control, but could allow for minor mischief.

MS suggested a workaround last month while it worked on a patch. The job is finished now, and the crucial 2002 patch is available here, while the more or less optional 2K patch is available here.



A CSS (

cross-site scripting

) vulnerability in Hotmail which could have allowed for considerable HTML mischief was sorted out before it became popular, thanks to

WhiteHat Security

which found it and alerted MS.

At issue is the possibility that outside content can get past HTML and JavaScript filters and into a dynamic HTML Web page, from which it could execute arbitrary code on a victim's machine.

In spite of filtering, "obfuscated content may elude the current filters and execute within the users browser environment," according to the Whitehat bulletin.

A sample exploit might be an e-mail containing HTML like this:

<HTML><BODY>
<br><STYLE TYPE="application/x-javascript">
<br>alert('JavaScript has been Executed');
<br></STYLE>
<br></BODY></HTML>

The "application/x-javascript" TYPE attribute causes the following expression to be interpreted as JavaScript, Whitehat says.

The vulnerability was reported to MS on 10 August and by the fourteenth it was fixed. It still, however, affects Netscape, and any number of other Web applications. Makes you wish you could force your e-mail client to preview and display messages as text only....



Three vulnerabilities in MS ISA (Internet Security and Acceleration) Server 2000 are being addressed in a single patch. We have the denial of service vulnerability involving the H.323 Gatekeeper Service which supports voice-over-IP traffic through the firewall, caused by a memory leak; the cross-site scripting vulnerability affecting error pages that ISA generates in response to a failed request for a web page; and the denial of service vulnerability in the in the proxy service, also caused by a memory leak. The relevant bulletin is

here

; and the patch is

here

.



A buffer overflow vulnerability in the Win-2K IrDA (infrared connection) driver could enable an attacker to cause an access violation on one's system and so cause a reboot. Since the attacker needs to be located within about two feet of the victim and have a direct line of sight to his infrared port, this one is pretty much a parlor trick. However, if anyone finds it more threatening than entertaining, MS has developed a patch for it, located

here

.

Intelligent flash storage arrays

More from The Register

next story
Nexus 7 fandroids tell of salty taste after sucking on Google's Lollipop
Web giant looking into why version 5.0 of Android is crippling older slabs
Be real, Apple: In-app goodie grab games AREN'T FREE – EU
Cupertino stands down after Euro legal threats
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
Microsoft: Your Linux Docker containers are now OURS to command
New tool lets admins wrangle Linux apps from Windows
Bada-Bing! Mozilla flips Firefox to YAHOO! for search
Microsoft system will be the default for browser in US until 2020
Facebook, working on Facebook at Work, works on Facebook. At Work
You don't want your cat or drunk pics at the office
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
The Heartbleed Bug: how to protect your business with Symantec
What happens when the next Heartbleed (or worse) comes along, and what can you do to weather another chapter in an all-too-familiar string of debilitating attacks?
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.