Microsoft have released a patch for IIS 4.0 which addresses the issues uncovered by eEye. The patch addresses multiple buffer overruns in modules that service .HTR, .STM, and .IDC file types. Note that this means the workaround released by Microsoft earlier this week is insufficient to properly protect you. Rather than try and include all of the URLs here in email, I have prepared a web page explaining the issue, the patch, and more importantly, some observations and recommendations. Please take a minute and see; http://ntbugtraq.ntadvice.com/default.asp?sid=1&pid=47&aid=38 Cheers, Russ - NTBugtraq Editor
Related pages