Skip to main content

Microsoft re-releases security patch

posted onNovember 18, 2004
by hitbsecnews

Microsoft has re-released a security patch for Internet Security and Acceleration (ISA) Server after a major code revision.

The updated patch, first released on 9 November, is for ISA Server 2000 and Microsoft Proxy Server 2.0. Details can be found here.

Users of Microsoft Small Business Server 2003 Premium Edition and Small Business Server 2000 are also advised to patch since this software uses the ISA code.

The patch is intended to plug a hole that could allow hackers to pretend that their code had been cleared as trusted content.

Microsoft warned that the flaw could be used to allow malicious software to be embedded in web pages that appear legitimate to casual users.

The company has also published a workaround for those unable or unwilling to patch. Microsoft recommends setting the DNS cache size to zero, effectively disabling DNS caching on the affected system.

This would prevent the affected software from using potentially spoofed data from the cache, but may have negative performance impact on DNS resolution.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th