webForumDet fria alternativet

Microsoft varnar för säkerhetshål i Exchange 5.5

Datasäkerhet

2 svar · 299 visningar · startad av inge

Medlem sedan sep. 2000498 inlägg
Frågan#1

Microsoft varnar för säkerhetshål i Exchange 5.5
10:13 - Computer Sweden: Företag som gjort det möjligt för sina anställda att komma åt sina e-postkonton via Microsoft Exchange 5.5:s webbgränssnitt riskerar att exponera kontona för skriptattacker via e-post. (Teknik) http://www.idg.se/idgse/default.asp

------------------
inge

Medlem sedan apr. 200010 782 inlägg
#2

MS skickade ut varning och patch dagarna innan IDG.se gick ut med det...

------------------
-"För övrigt stal hon mitt hjärta för evigt"

[Redigerat av stoffe-2k den 10 dec 2001]

Medlem sedan apr. 200010 782 inlägg
#3

fr 2001-12-07 00:35

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------
Title: Specially Formed Script in HMTL Mail can Execute in
Exchange 5.5 OWA
Date: 06 December 2001
Software: Microsoft Exchange 5.5 Server Outlook Web Access
Impact: Run Code of Attacker's Choice
Max Risk: Medium
Bulletin: MS01-057

Microsoft encourages customers to review the Security Bulletin at: http://www.microsoft.com/technet/security/bulletin/MS01-057.asp.
- ----------------------------------------------------------------------

Patch Availability:
===================
- A patch is available to fix this vulnerability. Please read the
Security Bulletin at
http://www.microsoft.com/technet/security/bulletin/ms01-057.asp
for information on obtaining this patch.

lö 2001-12-08 04:15

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------
Title: Specially Formed Script in HTML Mail can Execute in
Exchange 5.5 OWA
Date: 06 December 2001
Revised: 07 December 2001 (version 2.0)
Software: Microsoft Exchange 5.5 Server Outlook Web Access
Impact: Run Code of Attacker's Choice
Max Risk: Medium
Bulletin: MS01-057

Microsoft encourages customers to review the Security Bulletin at: http://www.microsoft.com/technet/security/bulletin/MS01-057.asp.
- -
- ----------------------------------------------------------------------

Reason for Revision:
====================
On December 6, 2001 Microsoft released the original version of this bulletin. On December 7, 2001 an issue relating to file dependencies for the patch was identified and the bulletin was updated and re-released to include this information. Specifically, for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequences may result. The "Caveats" section has been updated to include version requirements for this patch. In addition, it contains version recommendations for dependent components that are applicable at the time of this writing. In addition, the FAQ contains remediation information for customers who have applied this patch on systems with versions of IE older than 5.0.

------------------
-"För övrigt stal hon mitt hjärta för evigt"

[Redigerat av stoffe-2k den 10 dec 2001]

281 ms totalt · 4 externa anrop · v20260731065814-full.86ec41c2
130 ms — deklarationer (db)
0 ms — hämta statistik (cache)
148 ms — hämta tråd, inlägg och bilagor (db)
127 ms — ändringar (db)