MS quashes infamous Bofra bug
IFRAME fix
Posted in Anti-Virus, 2nd December 2004 11:40 GMT
Free Download - Security Web 2.0
Microsoft broke with its normal patching schedule yesterday to issue a fix for the notorious IFRAME vulnerability in Internet Explorer.
Windows XP SP2 users were immune to the vulnerability, which was exploited by the Bofra worm. Surfers using Mozilla Firefox and Opera browsers were not affected. But users of older versions of IE were left in the firing line from 2 November, when the vulnerability was discovered, until Microsoft’s cumulative patch yesterday.
Microsoft describes its fix for the IFRAME (AKA HTML Elements) vulnerability as critical. Users of IE 6.0 on Windows XP SP1, Windows 2000 (SP3 and SP4) and Windows NT4 are strongly urged to apply Microsoft’s cumulative patch. Microsoft's advisory is here.
Redmond's next scheduled monthly patch update is Tuesday, 7 December. ®
Related stories
Watch out there's an IE bug about
Bofra worm sets trap for unwary
Bofra exploit hits our ad serving supplier
Bofra exploit tied to 'massive botnet'

Implementing Energy Efficient Data Centers [WP114]
An Improved Architecture for High-Efficiency, High-Density Data Centers [WP126]
Web application security [3-2APYM3X]
Securing your Online Data Transfer with SSL
The Register Guide to Extended Validation

Inmate hacked prison network, broke into employee database
Miscreants hijacking machines via (freshly patched) Adobe flaw
Martial law planned for Craigslist's red-light district
Cocaine addicted IT manager hacks ex-employer's mail servers