When a user authenticates to a secured web page via Basic Authentication, IE caches the userid and password that were used, in order to minimize the number of times the user must authenticate to the same site. By design, IE should only send the cached credentials to secured pages on the site. However, it will actually send them to non-secure pages on the site as well. If a malicious user had complete control of another user’s network communications, he could wait until another user logged onto a secured site, then spoof a request for a non-secured page in order to collect the credentials.The vulnerability does not provide a means by which the malicious user could force the other user to log onto a secure page of his choice, and could only be used to reveal credentials that had been cached during the current IE session. Note: This patch is for Internet Explorer 5.x, but not 5.5 or higher. (Internet Explorer 5.5 is not affected by this vulnerability.) The patch requires IE 5.01 SP1 or higher to install. Customers who install this patch on other versions may receive a message reading 'This update does not need to be installed on this system'. This message is incorrect and should be ignored. Also, this venerability does affect IE 4.x; however, security patches for Internet Explorer 4.x are no longer being produced. Microsoft recommends that IE 4.x users who are concerned about this issue consider upgrading to either IE 5.01 SP1 or IE 5.5.
The VirtuaRAID is advanced RAID array application for software RAID solutions.
With VirtuaRAID you can consolidate up to 5 files in one virtual disk,...
The Microsoft Virtual Machine (Microsoft VM) is a platform-independent software engine that runs Java applets, applications, and COM objects. The Micr...
The Office 2000 SR-1a update includes the original Office 2000 SR-1 update and the Office 2000/Windows 2000 Registry Repair Utility. The functionality...
Office 2000 SP-2 provides the latest product updates to Office 2000 Service Release 1 (SR-1). Office 2000 SP-2 is particularly useful to corporate cus...
Office 2000 SP-2 provides the latest product updates to Office 2000 Service Release 1 (SR-1). Office 2000 SP-2 is particularly useful to corporate cus...
The Web Client Security Update for Office 2000 protects you from a vulnerability in Office 2000 that can allow login information to be sent over the I...
A free update to Office 97, consisting of a series of recent fixes and designed to make it even easier for customers to deploy Office 97. SR-2 include...
To help protect you against most viruses spread via attachments in e-mail, Microsoft has introduced a significant security enhancement for Outlook® 98...
To help protect you against most viruses spread via attachments in e-mail, Microsoft has introduced a significant security enhancement for Outlook® 98...
To help protect you against most viruses spread via attachments in e-mail, Microsoft has introduced a significant security enhancement for Outlook® 98...