According to a bulletin published on Microsofts Web site, "The NNTP (Network News Transport Protocol) service in Windows NT 4.0 and Windows 2000 contains a memory leak in a routine that processes news postings. Each time such a posting is processed that contains a particular construction, the memory leak causes a small amount of memory to no longer be available for use. If an attacker sent a large number of posts, the server memory could be depleted to the point at which normal service would be disrupted. An affected server could be restored to normal service by rebooting."
The company said the security vulnerability can potentially cause denial of service. According to Microsoft, "The vulnerability would not enable an attacker to compromise any data on the server, or to usurp any privileges on the machine."
The patches are available here.
IE Security Issues 1996-2002:: On October 16, 1998, Microsoft issue Security Bulletin MS98-015 and Knowledge when an IMAP mail message or an NNTP message with a 2-digit year as part http://www.nwnetworks.com/96-02iesecurity.htmHOME | Redmond Channel Partner Online | News: Opinion: Parsing Microsofts :: Security expert Russ Cooper surveys the field of Microsoft security bulletins for June, assessing often quoted by major media outlets on security issues. http://rcpmag.com/news/article.aspx?editorialsid=6775HOME | Securiteam: [NT] Cumulative Security Update for Internet Explorer (MS04-038):: Base Article 834707 documents the currently known issues that customers update that is included with Microsoft Security Bulletin http://www.derkeiler.com/Mailing-Lists/Securiteam/2004-10/0050.htmlHOME |
New IIS Patch the Ultimate Fix?
Northern Light Launches XML Portal |