M-082: Microsoft Cumulative Patch for Internet Explorer Privacy and Legal Notice

CIAC INFORMATION BULLETIN

M-082: Microsoft Cumulative Patch for Internet Explorer

[Microsoft Security Bulletin MS02-023]

May 23, 2002 21:00 GMT

PROBLEM: There are six new vulnerabilities in Internet Explorer.
  • Cross-Site Scripting in Local HTML Resource
  • Local Information Disclosure through HTML object
  • Script within Cookies Reading Cookies
  • Zone Spoofing through Malformed Web Page
  • Two "Content Disposition" Variants
A description of each vulnerability, if exploitable, is provided within Microsoft's Security bulletin.
PLATFORM: Internet Explorer 5.01, Internet Explorer 5.5, and Internet Explorer 6.0.
DAMAGE: The aggregate of severity is based on the types of systems affected by the vulnerability, their deployment patterns, and the effect that exploiting the vulnerability would have on them.
SOLUTION: Apply appropriate patch for appropriate Internet Explorer version as prescribed by Microsoft.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. The most serious vulnerability may allow an attacker to run code of choice.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/m-082.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-023.asp

[***** Start Microsoft Security Bulletin MS02-023 *****]

Microsoft Security Bulletin MS02-023  


15 May 2002 Cumulative Patch for Internet Explorer (Q321232)
Originally posted: May 15, 2002

Summary
Who should read this bulletin: Customers using Microsoft® 
Internet Explorer 

Impact of vulnerability: Six new vulnerabilities, the most serious
of which could allow code of attacker's choice to run.

Maximum Severity Rating: Critical 

Recommendation: Consumers using the affected versions of IE should 
install the patch immediately. 

Affected Software: 

Microsoft Internet Explorer 5.01 
Microsoft Internet Explorer 5.5 
Microsoft Internet Explorer 6.0 

Technical details

Technical description: 

This is a cumulative patch that includes the functionality of all 
previously released patches for IE 5.01, 5.5 and 6.0. In addition, 
it eliminates the following six newly discovered vulnerabilities:


Finally, it introduces a behavior change to the Restricted Sites zone. 
Specifically, it disables frames in the Restricted Sites zone. Since the 
Outlook Express 6.0, Outlook 98 and Outlook 2000 with the Outlook Email 
Security Update and Outlook 2002 all read email in the Restricted Sites zone 
by default, this enhancement means that those products now effectively 
disable frames in HTML email by default. This new behavior makes it impossible 
for an HTML email to automatically open a new window or to launch the download 
of an executable.

Mitigating factors: 

Cross-Site Scripting in Local HTML Resource:


Local Information Disclosure through HTML Object:


Script within Cookies Reading Cookies:


Zone Spoofing through Malformed Web Page:


New Variants of the "Content Disposition" Vulnerability:


Severity Rating:
Cross-Site Scripting in Local HTML Resource:

			Internet Servers 	Intranet Servers 	Client Systems
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Internet Explorer 5.01 	None 			None 			None 
Internet Explorer 5.5 	None 			None 			None 
Internet Explorer 6.0 	Moderate 		Moderate 		Critical
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Local Information Disclosure through HTML Object:

			Internet Servers 	Intranet Servers 	Client Systems
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Internet Explorer 5.01 	Moderate 		Moderate 		Critical 
Internet Explorer 5.5 	Moderate 		Moderate 		Critical 
Internet Explorer 6.0 	Moderate 		Moderate 		Critical
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Script within Cookies Reading Cookies:

			Internet Servers 	Intranet Servers 	Client Systems
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Internet Explorer 5.01 	None 			None 			None 
Internet Explorer 5.5 	Moderate 		Moderate 		Critical 
Internet Explorer 6.0 	Moderate 		Moderate 		Critical
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Zone Spoofing through Malformed Web Page:

			Internet Servers 	Intranet Servers 	Client Systems
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Internet Explorer 5.01 	Low 			Low 			Low 
Internet Explorer 5.5 	Low 			Low 			Low 
Internet Explorer 6.0 	Low 			Low 			Low
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

New Variants of the "Content Disposition" Vulnerability:

			Internet Servers 	Intranet Servers 	Client Systems
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Internet Explorer 5.01 	Moderate 		Moderate 		Moderate 
Internet Explorer 5.5 	None 			None 			None 
Internet Explorer 6.0 	Moderate 		Moderate 		Moderate
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Aggregate severity of all vulnerabilities eliminated by patch:

			Internet Servers 	Intranet Servers 	Client Systems
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Internet Explorer 5.01 	Critical 		Critical 		Critical 
Internet Explorer 5.5 	Critical 		Critical 		Critical 
Internet Explorer 6.0 	Critical 		Critical 		Critical
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
The above assessment is based on the types of systems affected by the vulnerability, 
their typical deployment patterns, and the effect that exploiting the vulnerability 
would have on them. The personal information disclosure vulnerabilities are most 
likely to affect client systems, based on usage patters. The variants of the 
"Content Disposition" vulnerability require knowledge of the software installed on a 
system by the user. The Zone Spoofing vulnerability requires NetBIOS access, which is 
commonly blocked at the perimeter firewall and by ISP's. The aggregate severity 
includes the severity of vulnerabilities announced in previously released security 
bulletins.

Vulnerability identifiers:


Tested Versions:
The following table indicates which of the currently supported versions of Internet 
Explorer are affected by the vulnerabilities. Versions of IE prior to 5.01 Service 
Pack 2 are no longer eligible for hotfix support. IE 5.01 SP2 is supported only via 
Windows® 2000 Service Packs and Security Roll-up Packages and on Windows NT® 4.0.

			IE 5.01 SP2 	IE 5.5 SP1 	IE 5.5 SP2 	IE 6.0
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Cross-Site Scripting in 
Local HTML Resource 
(CVE-CAN-2002-0189) 	No 		No 		No 		Yes

Local Information 
Disclosure through 
HTML object 
(CAN-2002-0191) 	Yes 		Yes 		Yes 		Yes

Script within Cookies 
Reading Cookies:
(CVE-CAN-2002-0192) 	No 		Yes 		Yes 		Yes

Zone Spoofing through 
Malformed Web Page
(CVE-CAN-2002-0190) 	Yes 		Yes 		Yes 		Yes

New Variants of the 
"Content Disposition" 
Vulnerability 
(CAN-2002-0193 and 
CAN-2002-0188) 		Yes 		No 		No 		Yes
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Patch availability

Download locations for this patch


Additional information about this patch

Installation platforms: 


Inclusion in future service packs:


Reboot needed:
Yes

Superseded patches:


Verifying patch installation:


Caveats:
None 

Localization:
Localized versions of this patch are available at the locations discussed in 
"Patch Availability"

Obtaining other security patches:
Patches for other security issues are available from the following locations:


Other information:

Acknowledgments

Microsoft thanks the following people for working with us to protect customers:


Support: 


Security Resources: The Microsoft TechNet Security Web Site provides additional 
information about security in Microsoft products.

Disclaimer: 
The information provided in the Microsoft Knowledge Base is provided "as is" without 
warranty of any kind. Microsoft disclaims all warranties, either express or implied, 
including the warranties of merchantability and fitness for a particular purpose. 
In no event shall Microsoft Corporation or its suppliers be liable for any damages 
whatsoever including direct, indirect, incidental, consequential, loss of 
business profits or special damages, even if Microsoft Corporation or its suppliers 
have been advised of the possibility of such damages. Some states do not allow the 
exclusion or limitation of liability for consequential or incidental damages so the 
foregoing limitation may not apply.

Revisions:


[***** End Microsoft Security Bulletin MS02-023 *****]


CIAC wishes to acknowledge the contributions of Microsoft Corporation for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/