Showing posts with label Internet explorer. Show all posts
Showing posts with label Internet explorer. Show all posts

Dubious HTTP III - Playing With Content-Length

The Content-Length header describes the size of the content, so there should be at most one. But what happens, when multiple Content-length headers get sent?

To determine the behavior of the browsers I tested with:
  • Microsoft Internet Explorer (MSIE) versions 8 and 10
  • Firefox 22
  • Google Chrome 28
  • Opera 12.16 (before WebKit)
  • Rekonq (KDE project) 2.2.1 - Konqueror (KDE) seems to behave the same

July's Patch Tuesday fixes Windows privilege system

On its July Patch Tuesday, Microsoft released a total of seven patch packages (bulletins). All except one of them close critical vulnerabilities. The company has closed a total of 34 holes in Windows, Internet Explorer, Office and many other products, among them the Windows kernel vulnerability that has affected the Windows privilege system for over a month.

http://www.h-online.com/security/news/item/July-s-Patch-Tuesday-fixes-Windows-privilege-system-1914459.html
Microsoft patch packages
Google security expert Tavis Ormandy discovered the kernel hole in May and didn't wait too long before disclosing details of it on the net. Shortly afterwards, an exploit followed that opens a Windows prompt at system privilege level – regardless of the user's actual privilege level. The hole, with CVE identification number CVE-2013-3660, affects all versions of Windows. 

Microsoft didn't warn its customers about the security problem ahead of the patch day despite, according to the company, the hole being exploited for targeted attacks. Talking to The H's associates at heise Security since the disclosure, Microsoft had only said that it was investigating the problem and was working on a solution. Patch bulletin MS13-053 closes further critical security holes, including an issue in the code for processing TrueType fonts, and should be installed as soon as possible.

Microsoft patch Tuesday to close kernel hole

Seven security updates, six of them classified as critical by Microsoft, will be closed on the upcoming patch Tuesday. The advance notice for the updates notes critical remote code execution holes in Microsoft's .NET framework, Silverlight, Office, Visual Studio, Lync and Internet Explorer. All versions of Windows are affected by at least three of the critical holes and all versions of Internet Explorer are affected by the critical flaw addressed by one of the fixes.
http://www.h-online.com/security/news/item/Microsoft-Patch-Tuesday-to-close-kernel-hole-1911898.html
Microsoft patch Tuesday to close kernel code
Microsoft patch Tuesday to close kernel hole | The H Security