Article ID: 269862 - Last Review: July 3, 2008 - Revision: 8.0 MS00-057: Patch released for canonicalization error issueThis article was previously published under Q269862 We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 7.0 running on Microsoft Windows Server 2008. IIS 7.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site: http://www.microsoft.com/technet/security/prodtech/IIS.mspx
(http://www.microsoft.com/technet/security/prodtech/IIS.mspx)
For more information about IIS 7.0, visit the following Microsoft Web site: http://www.iis.net/default.aspx?tabid=1
(http://www.iis.net/default.aspx?tabid=1)
On This PageSYMPTOMS A security patch has been released that resolves a
canonicalization error that can allow a malicious user to gain additional
permissions to certain types of files that are hosted on a Web
server. For this vulnerability to be exploited, several factors are involved:
276489
(http://support.microsoft.com/kb/276489/
)
Patch available for Web server folder traversal vulnerability
Microsoft Exchange 2000 Server users and Microsoft SharePoint Portal Server 2001 usersBoth Exchange 2000 and SharePoint Portal Server 2001 have problems with an older verison of this hotfix. A new update for the security patch for these products is available at the following Microsoft Web page:http://www.microsoft.com/technet/security/bulletin/ms00-086.mspx
(http://www.microsoft.com/technet/security/bulletin/ms00-086.mspx)
RESOLUTION To resolve this problem, obtain the latest
service pack for Windows 2000. For more information, click the following
article number to view the article in the Microsoft Knowledge Base: 260910
(http://support.microsoft.com/kb/260910/
)
How to obtain the latest Windows 2000 service pack
Internet Information Services 5.0The following files are available for download from the Microsoft Download Center:Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
The English version of this fix should have the
following file attributes or later:Date Time Version Size File name ----------------------------------------------------- 08-09-2000 1:02pm 5.0.2195.2103 357,136 W3svc.dll Internet Information Server 4.0The following files are available for download from the Microsoft Download Center:NOTE: Debug symbol files are required by an administrator to do both kernel and user mode debugging, providing a method to resolve global variables and function names in the loaded file. The symbol files are denoted with an "s" in the file name (for example, Prmcan4is.exe). US English
Intel:
Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() German
Intel:
Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Japanese
Intel:
Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Korean
Intel:
Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Simplified Chinese
Intel:
Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Traditional Chinese
Intel:
For additional information about how to download Microsoft Support
files, click the following article number to view the article in the Microsoft
Knowledge Base: Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() Collapse this image ![]() 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
The English version of this fix should have the
following file attributes or later:Date Time Size File name Platform --------------------------------------------------- 08/03/2000 05:06p 330,080 Asp.dll Intel 08/03/2000 05:04p 185,792 Infocomm.dll Intel 08/03/2000 05:05p 38,256 Ssinc.dll Intel 08/03/2000 05:05p 25,360 Sspifilt.dll Intel 08/03/2000 05:05p 228,496 W3svc.dll Intel 08/03/2000 05:08p 551,696 Asp.dll Alpha 08/03/2000 05:06p 304,912 Infocomm.dll Alpha 08/03/2000 05:07p 60,176 Ssinc.dll Alpha 08/03/2000 05:07p 39,696 Sspifilt.dll Alpha 08/03/2000 05:07p 384,272 W3svc.dll Alpha Microsoft Windows NT Server version 4.0, Terminal Server EditionTo resolve this problem, obtain the Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (SRP). For more information about the SRP, click the following article number to view the article in the Microsoft Knowledge Base:317636
(http://support.microsoft.com/kb/317636/
)
Windows NT Server 4.0, Terminal
Server Edition, Security Rollup Package
STATUSMicrosoft has confirmed that this is a problem in Internet
Information Services 5.0 and Internet Information Server 4.0.
MORE INFORMATION Additional information about this issue is available from
the following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/MS00-057.mspx
(http://www.microsoft.com/technet/security/bulletin/MS00-057.mspx)
You can find frequently asked questions about this vulnerability
at the following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/fq00-057.mspx
(http://www.microsoft.com/technet/security/bulletin/fq00-057.mspx)
| Article Translations
|

Back to the top

