Update Available For "Frame Spoof" Security Issue
This article was previously published under Q167614 SUMMARY
Microsoft has made an update available that addresses a potential security
issue with regard to the use of frames in Internet Explorer. Additional
information about this issue is available from the following Microsoft Web
site: http://www.microsoft.com/technet/security/Bulletin/MS98-020.mspx (http://www.microsoft.com/technet/security/Bulletin/MS98-020.mspx) Updates are available for the following products:
This update also fixes the "Untrusted Scripted Paste" and "Cross Frame Navigate" issues in Microsoft Internet Explorer 4.01 and 4.01 Service Pack 1 running on Windows operating systems. Additional information is available at the following Microsoft Web site: http://www.microsoft.com/windows/ie/community/columns/securityupgrade.mspx (http://www.microsoft.com/windows/ie/community/columns/securityupgrade.mspx)
After installing this update, "3214" is added to the "Update versions"
line when you click About Internet Explorer on the Help menu.
Note Internet Explorer 5 automatically includes protection against the "Frame Spoof" vulnerability at High security. To enable this protection in Internet Explorer 5 without using a High security setting, use the following steps:
MORE INFORMATION
Update Information by Product:
Warning This Frame Spoof patch may affect programs that host WebBroswer controls. Microsoft recommends you not install this patch if your program is affected. Note If you are using Internet Explorer 3.x or 4.0, you must install Internet Explorer 4.01 in order to apply this update. You can install Internet Explorer 4.01 with Service Pack 1 from the following Microsoft Web site: http://www.microsoft.com/windows/ie/downloads/default.mspx (http://www.microsoft.com/windows/ie/downloads/default.mspx)
Microsoft Internet Explorer 4.01 and 4.01 with Service Pack 1 for Windows
95:
Update File Name: 3214.exe Availability: http://www.microsoft.com/windows/ie/security (http://www.microsoft.com/windows/ie/security) Updated File Name Size (bytes) Date Version ------------------------------------------------------------- Mshtml.dll 2422032 12/19/98 4.72.3612.1700Microsoft Internet Explorer 4.01 and 4.01 with Service Pack 1 for Windows NT 4.0 x86:
Update File Name: 3214.exe Availability: http://www.microsoft.com/windows/ie/security (http://www.microsoft.com/windows/ie/security) Updated File Name Size (bytes) Date Version ------------------------------------------------------------- Mshtml.dll 2421520 12/19/98 4.72.3612.1700Microsoft Internet Explorer 4.01 and 4.01 with Service Pack 1 for Windows NT 4.0 Alpha:
Update File Name: 3214a.exe Availability: http://www.microsoft.com/windows/ie/security (http://www.microsoft.com/windows/ie/security) Updated File Name Size (bytes) Date Version ------------------------------------------------------------- Mshtml.dll 3948304 12/19/98 4.72.3612.1700Windows 98:
Update File Name: 3214.exe Availability: Microsoft Windows Update Updated File Name Size (bytes) Date Version ------------------------------------------------------------- Mshtml.dll 2422832 12/19/98 4.72.3612.1700Microsoft Internet Explorer 4.01 for Windows 3.1 and Windows NT 3.51:
Update File Name: 3214.exe Availability: http://www.microsoft.com/windows/ie/security (http://www.microsoft.com/windows/ie/security) Updated File Name Size (bytes) Date Version ------------------------------------------------------------ Mshtml16.dll 3086400 12/21/98 4.1.2512.2100Note After applying this update, cross-frame navigation will be permitted only in the following cases:
Internet Explorer Script Error An error has occurred in the script on this page.
Line: <line number>
Do you want to continue running scripts on this page?
Char: <character number> Error: Permission denied Code: <code number> APPLIES TO
| Article Translations
|
Back to the top
