Re: Problem with latest security update kb891781 (dhtmled.ocx update)

From: Pat Magnan (pat_at_sluggo.org)
Date: 02/15/05


Date: 15 Feb 2005 08:53:58 -0800

We have confirmed the problem in our company's application. It does
not appear resolvable by changing any setting on affected computers to
date. We created a simple test application (also in Delphi), and any
COM interface which used to be exposed to access the DOM object now
returns a NULL pointer, rather than allowing access to the object.

We tried importing the triedit.dll directly as a typelib, but still
have no method of getting access to the IHTMLDocument2 interface.

The only solution we can recommend to customers is to not deploy it,
which is a solution we really shouldn't have to recommend. Something
slipped through QA here, because you're not alone, a number of
applications are broken at this time.

I'm hoping either there's a fix to the fix, or we receive
documentation sometime soon on how we now use this control in
applications, 'safely' as it were.

"=?Utf-8?B?Z2VuWA==?=" <genX@discussions.microsoft.com> wrote in message news:<ED177C04-C595-49E7-A2D7-4B3622741F51@microsoft.com>...
> Hi,
> today I've installed latest security update kb891781, which caused, that our
> application for web content management that uses MSHTML editing ActiveX
> control dhtmled.ocx, stops work. Our application is developed in Delphi and
> uses this component for content managing.
> I found the problem (after tracing some debug info)- the application
> couldn't get access to the DOM (IHtmlEditDocument2 interface) through
> IHTMLEdit interface, so it raised the exception "Unknown interface".
> I didn't find any workaround than uninstall this security fix. Then
> everything was OK as before. Of course, I spent some time with security
> settings in IE - I enabled almost everything, but nothing helped.
>
> I tried to find whether some other has the same problem and I found some
> polish application based on this component having the same trouble.
>
> Does anybody has any idea where the problem is?
> Thanx.



Relevant Pages

  • security settings
    ... I somehow messed up my security settings and now I ... don't know how to fix them. ... I went to "control ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS Version and Interanl IP being Revealed
    ... Why would this be and how can I fix this. ... you could control the version via URLscan. ... in whatever that interface was migrated to with version 6. ...
    (microsoft.public.inetserver.iis.security)
  • 2.6 upgrade left machine unbootable
    ... Non-maintainer upload by The Security Team. ... Fix buffer overflow in XCF parser, ... local users to escape chroot restrictions ... Fix local DoS vulnerability that allows local users to panic ...
    (Debian-User)
  • Re: [Full-Disclosure] Was: Full Disclosure = Exploit Release - No disclosure No Fix
    ... Quality of fix would ... I don't expect the vendors who suck at getting things out ... which is a rare small percentage of security ... english forums. ...
    (Full-Disclosure)
  • NT4 terminal server security fix delinquency
    ... Since that time the Windows NT Server 4.0, Terminal Server Edition ... Security Roll-Up has still not been released, ... TSE Fix Status: To be release shortly ... TSE Fix Status: To be released shortly ...
    (NT-Bugtraq)