MS Corrects IE Patch Download Glitch

執筆者
Ryan Naraine
Ryan Naraine
Published: Aug 10, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Less than 24 hours after pushing out patches for three critical Internet Explorer vulnerabilities, Microsoft has re-released the bulletin to correct a glitch that blocked some users from downloading the patches.

Microsoft Corp. did not say how the corrupted files ended up on the Microsoft Download Center. A brief note appended to the re-released MS05-038 bulletin noted simply that the original packages were causing some “installation failures.”

On the Microsoft Security Response Center Weblog, a company spokesman explained the hiccup as a “corruption” that occurred in one of the final stages of publication.

The official made it clear the IE patches delivered via Windows Update, Microsoft Update, and the Windows catalog were unaffected by the corruption. “[If] you got the update from the download center in the first few hours after the 10 a.m. release, then the update you downloaded would not install,” he explained.

/zimages/4/28571.gifClick hereto read more about the original IE patch release.

” We immediately pulled the ability to get the updates from the Download Center, investigated the cause of the problem, and re-published the updates. The updates are now available on the Download center and we have re-released the bulletin to notify customers,” the spokesman added.

The cumulative IE update was part of the August release of six security bulletins from the software maker to cover eight vulnerabilities in the Windows operating system. The IE bulletin carries a “critical” rating and delivers patches for three separate remote code execution flaws in the worlds most widely used browser.

The most serious of the three is a flaw in the way IE handles JPEG images. An attacker could exploit the vulnerability by creating a malicious JPEG image and luring a Web surfer to view the image. “An attacker who successfully exploited this vulnerability could take complete control of an affected system,” the company said, adding that the malicious image could also be distributed via e-mail.

Advertisement

The bulletin also includes patches for a cross-domain flaw in IE that could lead to system takeover and information disclosure attacks. A third remote code execution bug was found in the way the browser instantiates COM Objects that are not intended to be used in Internet Explorer. This flaw could also be exploited by an attacker to take “complete control” of an unpatched system, Microsoft warned.

/zimages/4/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。