Critical Security Bulletin released for internet explorer!

Venom12

I made one post
Joined
Nov 23, 2008
Messages
25
http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx

Microsoft Security Bulletin MS08-078 - Critical

Security Update for Internet Explorer (960714)

Published: December 17, 2008
Version: 1.0

General Information

Executive Summary

This security update resolves a publicly disclosed vulnerability. The vulnerability could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

This security update is rated Critical for Internet Explorer 5.01, Internet Explorer 6, Internet Explorer 6 Service Pack 1, and Internet Explorer 7. For information about Internet Explorer 8 Beta 2, please see the section, Frequently Asked Questions (FAQ) Related to This Security Update. For more information, see the subsection, Affected and Non-Affected Software, in this section.

The security update addresses the vulnerability by modifying the way Internet Explorer validates data binding parameters and handles the error resulting in the exploitable condition. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection under the next section, Vulnerability Information.

This security update also addresses the vulnerability first described in Microsoft Security Advisory 961051.

Recommendation. Microsoft recommends that customers apply the update immediately.

Known Issues. None

Download, install, even if you don't use Internet Explorer.

Edit: Don't post your "[INSERT BROWSER HERE] IS BETTER" comments here please. :D
 
Last edited:
MS was getting a lot of fallout from this particular vulnerability. Some people were recommending to switch to another browser and wait for a patch.

*cough*
An independent study shows that, in 2006, IE users were vulnerable to online threats 78% of the time. Firefox users? Only 2%.

chart.png







?At risk? defined as publicly available exploits with no patch.
 
Yes, it takes only a few minutes (if that) to install it. There's no reason not to, even if you use Chrome, FF, Opera, or any other browser. :O

MS was getting a lot of fallout from this particular vulnerability. Some people were recommending to switch to another browser and wait for a patch.

*cough*
An independent study shows that, in 2006, IE users were vulnerable to online threats 78% of the time. Firefox users? Only 2%.

chart.png







“At risk” defined as publicly available exploits with no patch.

But it doesn't give any specific lists. So there's no way to know if that 78% is mostly harmless vulnerabilites, nor is there a way to tell if that 2% are not all extremely malicious vulnerabilites.

Less spewing of utterly useless data, more updating critical vulnerabilities.
 
Last edited:
I use FF, should I still update this thing?

YES!!!

They are going to stop support for Firefox 2 soon, so you better upgrade. If my Firefox logo isn't spinning that means you are using Firefox 2.

Chrome is nice it has a few problems but other than that it's good.
 
YES!!!

They are going to stop support for Firefox 2 soon, so you better upgrade. If my Firefox logo isn't spinning that means you are using Firefox 2.

Chrome is nice it has a few problems but other than that it's good.


This computer doesnt have FF but im pretty sure ive got FF3...
 
Thanks for the notification. I use firefox though.

Well you never know when a program will decide you need to use IE. Off the top of my head, I'm pretty sure Steam uses IE, along with YIM and my ATI driver updates open up in IE.

Anyway, don't update at your own risk. Whatever. :rolleyes:
 
Well you never know when a program will decide you need to use IE. Off the top of my head, I'm pretty sure Steam uses IE, along with YIM and my ATI driver updates open up in IE.

Anyway, don't update at your own risk. Whatever. :rolleyes:

I did update... Just saying. Default programs can be changed I'm pretty sure, so...



Hahah Trippin'?
 
yea i got the news from microsoft sent to my email, the funny thing was that it went to junk (microsoft even filters their own emails lol)
 
Back
Top