main

June 2003, Cumulative Patch for Internet Explorer

me101 on 04 June 2003 - 18:38 · 13 comments & 1796 views

Advertisement (Why?)
This is a cumulative patch that includes the functionality of all previously released patches for Internet Explorer 5.01, 5.5 and 6.0. In addition, it eliminates two newly discovered vulnerabilities:
  • A buffer overrun vulnerability that occurs because Internet Explorer does not properly determine an object type returned from a web server. It could be possible for an attacker who exploited this vulnerability to run arbitrary code on a user's system. If a user visited an attacker’s website, it would be possible for the attacker to exploit this vulnerability without any other user action. An attacker could also craft an HTML email that attempted to exploit this vulnerability.
  • A flaw that results because Internet Explorer does not implement an appropriate block on a file download dialog box. It could be possible for an attacker to exploit this vulnerability to run arbitrary code on a user's system. If a user simply visited an attacker’s website, it would be possible for the attacker to exploit this vulnerability without any other user action. An attacker could also craft an HTML email that attempted to exploit this vulnerability.
In order to exploit these flaws, the attacker would have to create a specially formed HTML email and send it to the user. Alternatively an attacker would have to host a malicious web site that contained a web page designed to exploit these vulnerabilities. The attacker would then have to persuade a user to visit that site.

As with the previous Internet Explorer cumulative patches released with bulletins MS03-004 and MS03-015, this cumulative patch will cause window.showHelp( ) to cease to function if you have not applied the HTML Help update. If you have installed the updated HTML Help control from Knowledge Base article 811630, you will still be able to use HTML Help functionality after applying this patch.

Download: Cumulative Patch for Internet Explorer (818529) [Select your language]
View: Microsoft Security Bulletin MS03-020 - Cumulative Patch for Internet Explorer (818529)
News source: Microsoft Internet Explorer Critical Patch


During first stage of V5 beta, we will be concentrating on two major issues:
WU Web Site beta testing - including gross and detailed site functionality, site UI, and site text
  1. WU content Beta testing - all content delivered through the WU site (with the exception of Security Updates, there is another channel for those) will have a specific beta release/test period. This includes driver update content.
  2. After the initial beta period, the WU V5beta program will continue to be involved in Beta update testing of software and driver content prior to their RTW ('going live') on the v5 site.
  3. Platform - current plans for V5 Beta are that all beta testers will require a platform of windows 2000 SP2 and later, for a testing platform.
  4. No one in either WU Beta or Office Beta groups have been enrolled in the V5 beta program, yet.
Neowin Note: This is probably the reason for the previous questionnaire on betaplace asking "Which Operating systems do you want to see on Windows Update" so if you haven't completed the questionnaire yet now might be a good time to do so.

Post a comment · Send to friend Comments · There are 13 additional comments
(2 replies) #1 DjmUK on 04 Jun 2003 - 19:03
Anyone else having problems installing this?
#1.1 Jason on 04 Jun 2003 - 19:07
Nope.
#1.2 Davey on 05 Jun 2003 - 05:11
Yep i had issues.

Only cos my catroot2 folder was corrupt. ZCuldnt install any Win Update.

What message you get?

PM me instead of replying in here.
#2 kainashi on 04 Jun 2003 - 19:28
installed mine fine.
#3 tmaxxtigger on 04 Jun 2003 - 20:00
If you're on the Windows Update beta program, be sure to switch back by running their little script.
#4 Jedimark on 04 Jun 2003 - 20:04
Worked fine for me
(1 reply) #5 Sierra on 04 Jun 2003 - 20:37
Wondering now... Are all the patches needed even if a firewall is used?!?!?!
#5.1 mAcOdIn on 05 Jun 2003 - 13:44
Patches are more important than a firewall in my opinion. Even if you have a firewall you still have to give internet explorer permission to get on the net, and you probably have given permission for other apps to connect to IE as well. You pretty much have to browse the internet. So a firewall doesn't really protect IE at all, so yeah you need the patches anyways.
(1 reply) #6 rseiler on 04 Jun 2003 - 20:53
Worked fine, as the IE and OE Cumulatives always have for me.

#5 re firewalls, that's a common misnomer. See here:
http://www.langa.com/newsletters/2003/2003-05-26.htm
#6.1 Sierra on 04 Jun 2003 - 23:08
Thx for the link
#7 antsy on 04 Jun 2003 - 22:22
looks like this months update
#8 cork1958 on 05 Jun 2003 - 02:46
Worked fine for me on all 4 systems.
#9 Phillip on 05 Jun 2003 - 06:57
installed mine fine too

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)