MS02-012/Q313450

From: Vladimir Ivanov (vivanov@tmsoft-ltd.kiev.ua)
Date: 02/28/02


From: "Vladimir Ivanov" <vivanov@tmsoft-ltd.kiev.ua>
To: <focus-ms@securityfocus.com>
Date: Thu, 28 Feb 2002 15:29:37 +0200


        Hi All!

    "Microsoft has released a patch for Windows 2000 that will eliminate a
vulnerability that exists because a malicious user could issue a specially
formatted, non-RFC compliant SMTP command that will result in a Denial of
Service attack. This would be carried out more typically through a custom
application where the malformed data would cause the SMTP service to fail.
Download now to prevent a possible Denial of Service Attack."

Patch is available to download:
http://download.microsoft.com/download/win2000platform/Patch/Q313450/NT5/EN-
US/Q313450_W2K_SP3_X86_EN.exe

I just download this patch and look at the files containted into it:
symbols/
aqueue.dll
asp.dll ????????
fscfg.dll
ftpctrs2.dll
ftpmib.dll
hotfix.exe
hotfix.inf
httpmib.dll
infoadmn.dll
infocomm.dll
isatq.dll
mailmsg.dll
ntfsdrv.dll ??????
smtpsvc.dll
sp3.cat
spmsg.dll
w3ctrs.dll

Does anybody know
            what asp.dll and ntfsdrv.dll doing in this patch ?

Thanx.
Vladimir Ivanov



Relevant Pages

  • RE: MS02-012/Q313450
    ... Download now to prevent a possible Denial of Service Attack." ... I just download this patch and look at the files containted into it: ...
    (Focus-Microsoft)
  • RE: MS02-012/Q313450
    ... Download now to prevent a possible Denial of Service Attack." ... Patch is available to download: ...
    (Focus-Microsoft)
  • Re: [PATCH -mm] vmscan: make mapped executable pages the first class citizen
    ... could easily lead to a denial of service attack, ... The point remains that the proposed patch does not solve the general ... Which loads benefit from this patch? ... A significant change to the reclaim algorithm also needs to ...
    (Linux-Kernel)
  • Re: [PATCH -mm] vmscan: make mapped executable pages the first class citizen
    ... could easily lead to a denial of service attack, ... The point remains that the proposed patch does not solve the general ... Which loads benefit from this patch? ... A significant change to the reclaim algorithm also needs to ...
    (Linux-Kernel)
  • Re: Latest kernel patch in 10.0 does not install
    ... Is there some reason that you think you need to keep up with the ... Considering the last patch was for a remote denial of service attack ... vulnerability, I would assume he updated the kernel for security reasons, ...
    (alt.os.linux.suse)