
70 vulnerabilities so far this year...
By Robert Lemos
Published: 26 September 2002 08:02 BST
Microsoft warned website administrators yesterday that a flaw in its FrontPage extensions could allow an attacker to take control of their servers or cause computers to seize up.
In its 53rd advisory for the year, the software giant said a vulnerability in the SmartHTML interpreter could be exploited to cause a denial-of-service attack on the web server if the computer had FrontPage Server Extensions 2000 running. For FrontPage Server Extensions 2002, the flaw could result in the attacker running the code of their choice, essentially taking control of the server.
"If a request for a certain type of web file is made in a particular way... [it could cause] the SmartHTML interpreter to cycle endlessly, consuming all the server's CPU availability," according to Microsoft's advisory.
The company urged administrators to apply the patch for the problem or run the Internet Information Server lockdown tool, a security application that disables many of the potentially dangerous functions in Microsoft's IIS web server.
Despite launching its Trustworthy Computing initiative in January, the software giant has racked up more than 70 vulnerabilities outlined in 53 advisories this year. Last week, Microsoft revealed three flaws in its Java virtual machine software.
The same day, the government unveiled the National Strategy for Securing Cyberspace. While the strategy urged companies and security researchers to solve vulnerability issues quickly and discretely, it didn't highlight software companies' difficulties in eliminating such problems.
Microsoft credited Digital Defense Services for finding the problem.
Robert Lemos writes for CNET News.com.
Linux System Administrators- London- Linux- Unix- TCP/IP- DNS- DHCP-Mysql-Oracle- Redhat- Windows- 40k An exciting opportunity has arisen for an ...
Global Technolgy Giant- System Administrators- Linux-Unix- TCP/IP- Scripting-Databases-London- 40k My client is a global leading award winning ...
System Administrators/ Unix/ Linux/ TCP/IP/ Scripting/ DNS/ DHCP/ TCP/IP/ 24/7 Are you technology focused? Are you an experienced Linux system ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...