Re: Microsoft Security Bulletin - MS02-011 and MS02-012

From: Evan Mann (emann@QUESTINC.ORG)
Date: 02/28/02


Date:         Thu, 28 Feb 2002 08:07:26 -0500
From: Evan Mann <emann@QUESTINC.ORG>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

The Exchange v5.5 patch from MS02-011 points to an Exchange 5.5 post SP4
patch that was released way back in October of 2001. I can't seem to find
anything that indicates this patch has changed since it's release date and
the release of MS02-011 which references this Exchange patch (Exchange 5.5
IMC Patch 2655.55). Is this patch infact, un-changed, and this is just
another exploit that effected the files this old Exchange 5.5 patch had
repaired back in October 2001?

-----Original Message-----
From: Russ [mailto:Russ.Cooper@RC.ON.CA]
Sent: Wednesday, February 27, 2002 11:19 PM
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Subject: Re: Microsoft Security Bulletin - MS02-011 and MS02-012

After reading the two new bulletins, some may find them a bit confusing.

Both MS02-011 and MS02-012 point to the same patch when the Windows 2000
SMTP service (the one in IIS) is involved. This makes sense, if you
think about it, one patch addresses both issues.

However, MS02-011 involves a vulnerability that affects not only the
Windows 2000 SMTP Service, but also the Internet Mail Connector in
Exchange Server 5.5. As such, MS02-011 has a patch for Exchange 5.5
environments also. Further, this vulnerability involves authentication
against the SMTP service using NTLM. Since Windows 2000 Pro and Windows
XP Pro are not listed as being affected, we just have to assume they
aren't able to do the same authentication process that W2K Server can
(despite the fact they can install the ?same? SMTP Service).

MS02-012 involves a vulnerability in an SMTP command. Exchange 5.5 does
not have a problem with whatever command is vulnerable, whereas the SMTP
Service (the one in IIS) does, ergo, there's a patch there for both
Windows 2000 environments and Windows XP Pro.

If you ask me, it's the right way for Microsoft to inform us of the
issues (although they could explain this in their bulletins instead of
me here). Each issue has its own bulletin (unlike the last IE bulletin),
even if it does mean the same patch is linked by both bulletins (for
some platforms).

Hope this is as clear as mud. Of course I could be completely wrong, it
just takes too long for me to get an answer out of MSRC these days
(they're obviously very busy folks) so I'm taking a stab at explaining
this based on my own *assum*ptions.

Cheers,
Russ - NTBugtraq Editor

oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Delivery co-sponsored by VeriSign - The Internet Trust Company
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Do you have 128-bit SSL encryption server security?
Get VeriSign's FREE Guide, "Securing Your Web Site for Business," and learn
everything you need to know about using 128-bit SSL to encrypt your
e-commerce transactions, secure your intranets and authenticate your Web
site. 128-bit SSL is serious security for your online business. Get it now!
http://www.verisign.com/cgi-bin/go.cgi?a=n094765650008000
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo



Relevant Pages

  • Re: Microsoft Security Bulletin MS02-025
    ... upgrade my entire Exchange organization to SP2 in order to apply this patch? ... > Software: Microsoft Exchange ... > seek to exploit this flaw and mount a denial of service attack. ...
    (microsoft.public.security)
  • Re: Apply KB926666 on FE E2k3 box?
    ... If I were merely running an Exchange 2k3 enviornment then it'd ... patch all client OS's ... Run Time Zone Update tool (against all Exchange servers, ...
    (microsoft.public.exchange.admin)
  • RE: SBS 2003 Basic - E-mail Addresses not added
    ... You're experiencing the symptoms addressed by the KB 837444 patch for Exchange 2003. ... If you want to obtain the KB 837444 patch, you will need to open up a support case with Microsoft Product Support first. ... Microsoft Small Business Server Support ... SBS 2000: microsoft.public.backoffice.smallbiz2000 ...
    (microsoft.public.windows.server.sbs)
  • Re: Question on Security Update for Exchange 2003
    ... The cost to setup a lab environment is not extremely high. ... performed a backup just for a security patch. ... So here the person posts that they have taken over Exchange duties, ...
    (microsoft.public.exchange.admin)
  • Potential Problem with Microsoft Security Bulletin MS01-057
    ... Potential issue with this security patch. ... Issue is with an older version of IE on the exchange server. ... Earn 5% rebate on licenses purchased for Trend Micro ScanMail for ... Microsoft Exchange 2000 between October 1 and November 16. ...
    (NT-Bugtraq)