MinorRev: Microsoft Security Bulletin MS03-051 - Buffer Overrun in Microsoft FrontPage Server Extensions Could Allow Code Execution (813360)

From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 12/11/03

  • Next message: Russ: "Re: IE URL obfuscation"
    Date:         Wed, 10 Dec 2003 21:12:32 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Reason for Revision:
    V1.4 December 10, 2003: Updated the FAQ section to reflect a new Windows
    Update offering on Windows XP.

    Microsoft Security Bulletin MS03-051:
    Buffer Overrun in Microsoft FrontPage Server Extensions Could Allow Code
    Execution (813360)

    Bulletin URL:
    http://www.microsoft.com/technet/security/bulletin/MS03-051.asp

    Summary:
     Version Number: V1.4
     Revision Date: 12-10-2003
     Impact of Vulnerability: Remote Code Execution
     Maximum Severity Rating: Critical
     Patch(es) Replaced: This update replaces the security updates contained
    in the following bulletins: MS01-035 and MS02-053.
     Caveats: None
     CVE Number(s): CAN-2003-0822,CAN-2003-0824

    Tested Software:
     Affected Software:
     * Microsoft Windows 2000 Service Pack 2, Service Pack 3
     * Microsoft Windows XP, Microsoft Windows XP Service Pack 1
     * Microsoft Office XP, Microsoft Office XP Service Pack 1, Service Pack
    2

     Affected Components:
     * Microsoft FrontPage Server Extensions 2000
    <http://www.ntbugtraq.com/link/C84C3D10-A821-4819-BF58-D3BC70A77BFA.asp>
     * Microsoft FrontPage Server Extensions 2000 (Shipped with Windows
    2000)
    <http://www.ntbugtraq.com/link/057D5F0E-0E2B-47D2-9F0F-3B15DD8622A2.asp>
     * Microsoft FrontPage Server Extensions 2000 (Shipped with Windows XP)
    <http://www.ntbugtraq.com/link/9B302532-BFAB-489B-82DC-ED1E49A16E1C.asp>
     * Microsoft FrontPage Server Extensions 2002
    <http://www.ntbugtraq.com/link/3E8A21D9-708E-4E69-8299-86C49321EE25.asp>
     * Microsoft SharePoint Team Services 2002 (Shipped with Office XP)
    <http://www.ntbugtraq.com/link/5923FC2F-D786-4E32-8F15-36A1C9E0A340.asp>

     Software Not Affected:
     * Microsoft Windows Millennium Edition
     * Microsoft Windows NT Workstation 4.0, Service Pack 6a
     * Microsoft Windows NT Server 4.0, Service Pack 6a
     * Microsoft Windows NT Server 4.0, Terminal Server Edition, Service
    Pack 6
     * Microsoft Windows 2000 Service Pack 4
     * Microsoft Windows XP 64-Bit Edition Version 2003
     * Microsoft Windows Server 2003 (Windows SharePoint Services)
     * Microsoft Windows Server 2003 64-Bit Edition (Windows SharePoint
    Services)
     * Microsoft Office System 2003

    This email is sent to NTBugtraq automagically as a service to my
    subscribers. (v2.2)

    Cheers,
    Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor

    ----
    NTBugtraq subscribers save $103.00 off the TICSA exam by using promo
    code "NT1003" when registering to take the TICSA exam at www.2test.com.
    Prove to your employer and peers that you have the knowledge and
    abilities to be an active stakeholder in today's enterprise security.
    Become TICSA certified www.trusecure.com/ticsa.  Promotion expires
    12/31/03 and cannot be used in combination with other offers.
    ----
    

  • Next message: Russ: "Re: IE URL obfuscation"

    Relevant Pages

    • RE: Windows 2000 VPN No Longer Connecting
      ... VPN Client Cannot Establish a Connection After You Install a Service Pack ... This article contains information about modifying the registry. ... your Windows XP or Windows 2000 PPTP client to your corporate network, ... obtain the latest service pack for Microsoft ...
      (microsoft.public.win2000.networking)
    • [NT] Buffer Overrun in JPEG Processing (GDI+) Allows Code Execution (MS04-028)
      ... privately reported vulnerability. ... * Microsoft Windows XP and Microsoft Windows XP Service Pack 1 ...
      (Securiteam)
    • Re: Remote Access Wizard - SBS 2003 SP1
      ... Windows Server 2003 Service Pack 1 ... Windows SharePoint Services 2.0 Service Pack 1 ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • SecurityFocus Microsoft Newsletter #176
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #49
      ... Subject: SecurityFocus Microsoft Newsletter #49 ... Microsoft Windows NNTP Denial of Service Vulnerability ... Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability ... Microsoft ISA Server H.323 Memory Leak Denial of Service... ...
      (Focus-Microsoft)