Article ID: 322273 - Last Review: October 29, 2007 - Revision: 5.9 MS02-033: Commerce Server 2002 and Commerce Server 2000 security updatesThis article was previously published under Q322273 On This PageSYMPTOMS
Microsoft has released patches for Commerce Server 2002 and Commerce Server 2000 that include updates for the following security vulnerabilities: Profile service buffer overrun This vulnerability results because the Profile Service contains an unchecked buffer in a section of code that handles certain types of API calls. The Profile Service can be used to enable users to manage their own profile information and to research the status of their order. An attacker who provides specially malformed data to certain calls that are exposed by the Profile Service can cause the Commerce Server process to fail, or can run code in the LocalSystem security context. This vulnerability only affects Commerce Server 2000.
This is a buffer overrun vulnerability in the Office Web Components (OWC) package installer that is used by Commerce Server. An attacker who provides specially malformed data as input to the OWC package installer can cause the process to fail, or can run code in the LocalSystem security context. This vulnerability only affects Commerce Server 2000.
This is a vulnerability in the Office Web Components (OWC) package installer that is used by Commerce Server. An attacker who invokes the OWC package installer in a particular manner can cause commands to be run on the Commerce Server according to the permissions that are associated with the log on credentials that the attacker uses. This vulnerability only affects Commerce Server 2000.
317615
(http://support.microsoft.com/kb/317615/
)
MS02-010: Unchecked buffer in ISAPI filter may allow Commerce Server compromise
RESOLUTIONCommerce Server 2002To resolve this problem, install Commerce Server 2002 Service Pack 1 (SP1). For more information, click the following article number to view the article in the Microsoft Knowledge Base:328814
(http://support.microsoft.com/kb/328814/
)
How to obtain the latest Commerce Server 2002 service pack
Commerce Server 2000To resolve this problem, install Commerce Server 2000 Service Pack 3 (SP3). For more information, click the following article number to view the article in the Microsoft Knowledge Base:297216
(http://support.microsoft.com/kb/297216/
)
How to obtain the latest Commerce Server 2000 service pack
STATUS
Microsoft has confirmed that this problem may cause a degree of security vulnerability in the Microsoft products that are listed in the "Applies to" section.
This problem was first corrected in Commerce Server 2000 Service Pack Service Pack 3 and Commerce Server 2002 Service Pack 1. MORE INFORMATION
For more information about these vulnerabilities, visit the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/MS02-033.mspx
(http://www.microsoft.com/technet/security/bulletin/MS02-033.mspx)
| Article Translations
|
Back to the top
