Madrid, August 3, 2004 - Microsoft has published the security bulletin MS04-025 (*) announcing the availability of a critical update for Internet Explorer, which resolves three recently discovered vulnerabilities that allow code to be executed remotely.
The first security flaw lies in the fact that Internet Explorer does not correctly validate the security context of a frame that has been redirected by a web server. An attacker could exploit this vulnerability to construct a web page or email message (in HTML), which would allow code to be run when the user visited the page or viewed the message.
The second security problem is a buffer overflow that exists in how Internet Explorer processes BMP image files. Finally, the third vulnerability exists in the processing of GIF files, as the routine that frees up memory could try to free up the same memory space more than once, which could result in a denial of service or even allow code to be run.
(*) The security bulletin offering detailed information about these vulnerabilities and the addresses for downloading the updates released by Microsoft is available at: http://www.microsoft.com/technet/security/bulletin/ms04-025.mspx
Oxygen3 24h-365d, by Panda Software
© Panda Software 2003
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel