Article ID: 928139 - Last Review: May 10, 2007 - Revision: 2.2

FIX: You may experience several security-related issues in Microsoft XML components in Windows CE 6.0

On This Page

Expand all | Collapse all

SYMPTOMS

You may experience the following security-related issues in Microsoft XML (MSXML) components in Microsoft Windows CE 6.0:
  • A cross-site scripting vulnerability exists.
  • An MSXML component may enter an infinite loop.
  • MSXML crashes.

RESOLUTION

Software update information

The fixes in this Windows CE 6.0 software update have been converted from the desktop Microsoft Windows version of MSXML code to Windows CE 6.0.

A supported software update is now available from Microsoft as Windows CE 6.0 Platform Builder Monthly Update (December 2006). You can confirm this by scrolling to the "File information" section of this article. The package file name contains the product version, date, Knowledge Base article number, and processor type. The package file name format is:
Product version-yymmdd-kbnnnnnn-processor type
For example: Wincepb50-060503-kb917590-armv4i.msi is the ARMV4i Windows CE 5.0 Platform Builder fix that is documented in KB article 917590 and that is contained in the May 2006 monthly update. To resolve this problem immediately, click the following article number for information about obtaining Windows CE Platform Builder and core operating system software updates:
837392  (http://support.microsoft.com/kb/837392/ ) How to locate core operating system fixes for Microsoft Windows CE Platform Builder products

Prerequisites

This update is supported only if all previously issued updates for this product have also been installed.

Restart requirement

After you install this update, you must perform a clean build of the whole platform. To clean the platform, click Clean on the Build menu. To build the platform, click Build Platform on the Build menu. You do not have to restart your computer after you apply this update.

Update replacement information

This update does not replace any other updates.

File information

The English version of this package has the file attributes (or later file attributes) that are listed in the following table.
Collapse this tableExpand this table
File nameFile sizeDateTime
Wincepb60-061220-kb928139-armv4i.msi16,028,67221-Dec-200600:47
Wincepb60-061220-kb928139-mipsii.msi15,296,00021-Dec-200600:47
Wincepb60-061220-kb928139-mipsii_fp.msi15,306,75221-Dec-200600:46
Wincepb60-061220-kb928139-mipsiv.msi15,430,14421-Dec-200600:47
Wincepb60-061220-kb928139-mipsiv_fp.msi15,432,19221-Dec-200600:47
Wincepb60-061220-kb928139-sh4.msi14,947,32821-Dec-200600:47
Wincepb60-061220-kb928139-x86.msi12,729,85621-Dec-200600:47
The English version of this update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
Collapse this tableExpand this table
File nameFile sizeDateTimePath
Xmldom.lib9,056,95614-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlhttp.lib268,35214-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlislands.lib835,11014-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlmime.lib1,292,96814-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlminisax.lib3,978,10214-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlnetfull.lib201,18214-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlnetmini.lib110,36614-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlsax.lib2,618,53014-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlstubs.lib163,89014-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlxql.lib4,663,39214-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmlxslt.lib4,559,41214-Dec-200605:25public\ie\oak\lib\armv4i\debug
Xmldom.lib8,766,40614-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlhttp.lib246,43814-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlislands.lib815,05014-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlmime.lib1,269,23214-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlminisax.lib3,864,86814-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlnetfull.lib193,89214-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlnetmini.lib105,09214-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlsax.lib2,517,08814-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlstubs.lib160,24414-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlxql.lib4,544,35214-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmlxslt.lib4,392,23814-Dec-200602:53public\ie\oak\lib\armv4i\retail
Xmldom.lib9,045,60414-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlhttp.lib261,67014-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlislands.lib848,24814-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlmime.lib1,300,90614-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlminisax.lib3,921,33814-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlnetfull.lib203,49814-Dec-200610:29public\ie\oak\lib\mipsii\debug
Xmlnetmini.lib112,13814-Dec-200610:29public\ie\oak\lib\mipsii\debug
Xmlsax.lib2,619,09614-Dec-200610:29public\ie\oak\lib\mipsii\debug
Xmlstubs.lib161,81014-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlxql.lib4,719,97614-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmlxslt.lib4,596,99014-Dec-200610:30public\ie\oak\lib\mipsii\debug
Xmldom.lib8,329,89814-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlhttp.lib243,63214-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlislands.lib777,62014-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlmime.lib1,144,74014-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlminisax.lib3,652,82214-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlnetfull.lib186,39414-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlnetmini.lib103,55014-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlsax.lib2,430,14214-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlstubs.lib136,29414-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlxql.lib4,179,64614-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmlxslt.lib4,091,63814-Dec-200607:59public\ie\oak\lib\mipsii\retail
Xmldom.lib9,048,52014-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlhttp.lib261,68614-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlislands.lib848,41014-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlmime.lib1,301,05014-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlminisax.lib3,923,75814-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlnetfull.lib203,54014-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlnetmini.lib112,16814-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlsax.lib2,619,51614-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlstubs.lib162,00614-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlxql.lib4,720,07814-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmlxslt.lib4,598,49414-Dec-200615:30public\ie\oak\lib\mipsii_fp\debug
Xmldom.lib8,334,46414-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlhttp.lib243,64414-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlislands.lib777,77014-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlmime.lib1,144,88214-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlminisax.lib3,656,81214-Dec-200613:01public\ie\oak\lib\mipsii_fp\retail
Xmlnetfull.lib186,45014-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlnetmini.lib103,58614-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlsax.lib2,430,55014-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlstubs.lib136,47614-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlxql.lib4,179,65014-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmlxslt.lib4,093,33414-Dec-200613:00public\ie\oak\lib\mipsii_fp\retail
Xmldom.lib9,131,66814-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlhttp.lib264,58214-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlislands.lib856,12414-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlmime.lib1,314,00614-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlminisax.lib3,963,23214-Dec-200620:38public\ie\oak\lib\mipsiv\debug
Xmlnetfull.lib206,03814-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlnetmini.lib113,53014-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlsax.lib2,644,81614-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlstubs.lib162,92614-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlxql.lib4,760,12014-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmlxslt.lib4,635,49014-Dec-200620:37public\ie\oak\lib\mipsiv\debug
Xmldom.lib8,397,79614-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlhttp.lib245,65214-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlislands.lib781,27814-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlmime.lib1,152,20014-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlminisax.lib3,684,55814-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlnetfull.lib188,57214-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlnetmini.lib104,98414-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlsax.lib2,445,23414-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlstubs.lib136,94814-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlxql.lib4,196,40014-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmlxslt.lib4,112,04414-Dec-200617:57public\ie\oak\lib\mipsiv\retail
Xmldom.lib9,132,31015-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlhttp.lib264,59815-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlislands.lib856,28615-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlmime.lib1,314,15015-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlminisax.lib3,963,41215-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlnetfull.lib206,08015-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlnetmini.lib113,56015-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlsax.lib2,645,23615-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlstubs.lib163,11415-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlxql.lib4,759,40815-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmlxslt.lib4,636,30615-Dec-200601:58public\ie\oak\lib\mipsiv_fp\debug
Xmldom.lib8,398,36414-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlhttp.lib245,66414-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlislands.lib781,43214-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlmime.lib1,152,33814-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlminisax.lib3,684,56614-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlnetfull.lib188,62614-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlnetmini.lib105,02014-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlsax.lib2,445,64614-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlstubs.lib137,13214-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlxql.lib4,195,07014-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmlxslt.lib4,112,98814-Dec-200623:28public\ie\oak\lib\mipsiv_fp\retail
Xmldom.lib8,324,77618-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlhttp.lib238,68418-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlislands.lib785,91218-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlmime.lib1,183,54018-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlminisax.lib3,594,58618-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlnetfull.lib185,77018-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlnetmini.lib101,88618-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlsax.lib2,427,08218-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlstubs.lib148,65818-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlxql.lib4,351,22818-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmlxslt.lib4,257,26418-Dec-200612:08public\ie\oak\lib\sh4\debug
Xmldom.lib7,679,53218-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlhttp.lib220,87018-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlislands.lib714,62618-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlmime.lib1,055,54818-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlminisax.lib3,362,62418-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlnetfull.lib171,46218-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlnetmini.lib95,54418-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlsax.lib2,224,57618-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlstubs.lib128,63018-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlxql.lib3,864,83818-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmlxslt.lib3,811,97618-Dec-200610:09public\ie\oak\lib\sh4\retail
Xmldom.lib7,216,83818-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlhttp.lib209,85618-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlislands.lib670,18418-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlmime.lib1,041,18818-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlminisax.lib3,178,74418-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlnetfull.lib162,22818-Dec-200616:45public\ie\oak\lib\x86\debug
Xmlnetmini.lib90,30618-Dec-200616:45public\ie\oak\lib\x86\debug
Xmlsax.lib2,122,18618-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlstubs.lib148,42418-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlxql.lib3,630,02418-Dec-200616:46public\ie\oak\lib\x86\debug
Xmlxslt.lib3,560,46818-Dec-200616:46public\ie\oak\lib\x86\debug
Xmldom.lib7,243,19218-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlhttp.lib205,99818-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlislands.lib675,14218-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlmime.lib1,071,29018-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlminisax.lib3,229,67218-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlnetfull.lib165,86218-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlnetmini.lib91,72618-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlsax.lib2,122,97618-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlstubs.lib152,14018-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlxql.lib3,650,66018-Dec-200614:33public\ie\oak\lib\x86\retail
Xmlxslt.lib3,560,80418-Dec-200614:33public\ie\oak\lib\x86\retail

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

MORE INFORMATION

For more information about an MSXML security-related update for Microsoft Windows CE .NET 4.2, click the following article number to view the article in the Microsoft Knowledge Base:
916644  (http://support.microsoft.com/kb/916644/ ) FIX: Update for several MSXML security issues in Windows CE .NET 4.2
For more information about a MSXML security-related update for Microsoft Windows CE 5.0, click the following article number to view the article in the Microsoft Knowledge Base:
918456  (http://support.microsoft.com/kb/918456/ ) FIX: You may experience security-related problems when you use MSXML components in Windows CE 5.0
For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684  (http://support.microsoft.com/kb/824684/ ) Description of the standard terminology that is used to describe Microsoft software updates

APPLIES TO
  • Windows Embedded CE 6.0
Keywords: 
kbbug kbfix kbqfe kbpubtypekc kbhotfixserver KB928139
 

Article Translations