ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Join ZDNet's roundtable on datacentres

Resources Downloads

Download Now

IIS5 Malformed URL Service Failure Vulnerability Patch MS01-014 (3/1/01)


License Free
Requirements Windows 2000, Microsoft Internet Information Services 5.0 (IIS 5.0) or Microsoft Exchange 2000
Downloads 146 Limitations None
Publisher Microsoft File Size 311k
Date added 04 Apr 2001 Check your speed

IIS 5.0 contains a flaw affecting the way that an URL is handled if it has a specific construction and its length is within a very narrow range of values. If such an URL were repeatedly sent to an affected system, a confluence of events could cause a memory allocation error that would result in the failure of the IIS service.

Exchange 2000 is affected by the same vulnerability. To support Web-based mail clients, it introduces the ability to address items on the store via URLs. This is done in part by using IIS 5.0, and in part via code that is specific to Exchange 2000. Both pieces of code contain the flaw, but the effect of exploiting the vulnerability via either would be the same--it could be used to cause the IIS service to fail, but could not be used to attack the Exchange service itself. That is, successfully attacking an Exchange server via this vulnerability would disrupt Web-based mail clients' use of the server, but not that of MAPI-based mail clients like Outlook.

Because the flaw occurs in two different code modules, one of which installs as part of IIS 5.0 and both of which install as part of Exchange 2000, it is important for Exchange 2000 administrators to install both this IIS patch, as well as the Exchange patch.

Download Now

Did you find this download useful?
27 out of 50 users found this download useful


People who downloaded this software also downloaded...

SpyWall Anti-Spyware 1.4.3.1

Remove spyware and keep them out with a browser sandbox.

More info +


Cute Password Manager 2008.1.3.8

Log into Web sites and fill forms with just a few mouse clicks.

More info +


SolidShare 2.6.11

Connect anyone on your network to the Internet with one ISP account and one modem.

More info +


EasyCryptor 1

Encrypt and decrypt any files and send results to your e-mail address.

More info +


Child Computer Lock 1.6

Protect your privacy by locking your computer.

More info +


Portable Vault 2.0.0.7

Protect sensitive information on your portable USB Drive.

More info +


Digital Vault 2.1.5.1

Encrypt, hide, and protect your personal data.

More info +


n-Pass2Go 2.7.0.465

Store and manage your passwords and encrypted data on any removable device.

More info +


Safe AutoLogon 1.5.93

Save Windows account information encrypted in AES/Triple-DES and log on automatically.

More info +


Anonymity Gateway 2.5

Mask your real IP while surfing and erase traces of online activity.

More info +



Download

Embarcadero Power SQL

Embarcadero PowerSQL simplifies SQL development for application developers with many features for improving productivity and reducing errors.

  • Downloads: 4,794
  • Requirements:
  • License: Vendor registration required
  • Publisher: Embarcadero
  • Size: 0

Download Now

Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec