Internet Explorer 4.51 & Outlook Express 5.01 Address Security, JavaScript Problems
Microsoft Corporation has released Internet Explorer 4.51 and Outlook Express 5.01, which address issues with Web site and email attachment security, as well as JavaScript problems that occur using the two products in combination. The two updates are available together as an 11.4 MB download, or separately (6.4 MB and 9.4 MB, respectively) if you only use one or the other. Microsoft has published a brief FAQ on these releases.
In a nutshell, Internet Explorer 4.51 includes new SSL version 3 security certificates from VeriSign. Some certificates which originally shipped with Internet Explorer 4.5 expire 01-Jan-00, at which point it will become impossible for Explorer to establish secure connections to some Web sites (such as online merchants or financial services). Both Internet Explorer 4.51 and Outlook Express 5.01 offer improved support for version 3 certificates that should allow automatic updating in the future. Installing Explorer 4.51 is a mere matter of drag & drop in the Finder.
Outlook Express 5.01 patches a security loophole first reported in mid-November whereby attachments could automatically be downloaded to a user’s hard drive by being embedded in a specifically composed MIME HTML (MHTML) message. These items would appear in a user’s Download folder without the user’s knowledge; if a user launched one of these items and it happened to be a malicious application, damage could occur. Outlook Express 5.01 protects users by not downloading any material embedded in an MHTML message that can’t be rendered as part of the message. Outlook Express 5.01 ships with an updated JavaScript shared library that’s also used by Internet Explorer; the version that shipped with Outlook Express 5.0 could cause Internet Explorer to have problems with certain secure Web sites. This problem only impacted users running both Internet Explorer 4.5 and Outlook Express 5.0 on the same Macintosh. Be careful using Outlook Express’s drag & drop installation feature: it’s all too easy to delete your existing mail database if you simply replace your existing Outlook Express folder.