Select the product you need help with
MS00-057: Patch released for canonicalization error issueArticle ID: 269862 This article was previously published under Q269862 We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 7.0 running on Microsoft Windows Server 2008. IIS 7.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site: http://www.microsoft.com/technet/security/prodtech/IIS.mspx For more information about IIS 7.0, visit the following Microsoft Web site:
(http://www.microsoft.com/technet/security/prodtech/IIS.mspx)
http://www.iis.net/default.aspx?tabid=1
(http://www.iis.net/default.aspx?tabid=1)
On This PageSymptoms A security patch has been released that resolves a
canonicalization error that can allow a malicious user to gain additional
permissions to certain types of files that are hosted on a Web
server. For this vulnerability to be exploited, several factors are involved:
276489
(http://support.microsoft.com/kb/276489/
)
Patch available for Web server folder traversal vulnerability
Microsoft Exchange 2000 Server users and Microsoft SharePoint Portal Server 2001 usersBoth Exchange 2000 and SharePoint Portal Server 2001 have problems with an older verison of this hotfix. A new update for the security patch for these products is available at the following Microsoft Web page:http://www.microsoft.com/technet/security/bulletin/ms00-086.mspx
(http://www.microsoft.com/technet/security/bulletin/ms00-086.mspx)
Resolution To resolve this problem, obtain the latest
service pack for Windows 2000. For more information, click the following
article number to view the article in the Microsoft Knowledge Base: 260910
(http://support.microsoft.com/kb/260910/
)
How to obtain the latest Windows 2000 service pack
Internet Information Services 5.0The following files are available for download from the Microsoft Download Center:Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/EN-US/Q269862_W2K_SP2_x86_en.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/AR/Q269862_W2K_SP2_x86_AR.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/CN/Q269862_W2K_SP2_x86_CN.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/TW/Q269862_W2K_SP2_x86_TW.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/CS/Q269862_W2K_SP2_x86_CS.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/DA/Q269862_W2K_SP2_x86_DA.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/NL/Q269862_W2K_SP2_x86_NL.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/FI/Q269862_W2K_SP2_x86_FI.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/FR/Q269862_W2K_SP2_x86_FR.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/DE/Q269862_W2K_SP2_x86_DE.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/EL/Q269862_W2K_SP2_x86_EL.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/HE/Q269862_W2K_SP2_x86_HE.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/HU/Q269862_W2K_SP2_x86_HU.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/IT/Q269862_W2K_SP2_x86_IT.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/JA/Q269862_W2K_SP2_x86_JA.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/patchNEC/q269862/NT5/JA/Q269862_W2K_SP2_NEC98_JA.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/KO/Q269862_W2K_SP2_x86_KO.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/NO/Q269862_W2K_SP2_x86_NO.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/PL/Q269862_W2K_SP2_x86_PL.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/PT-BR/Q269862_W2K_SP2_x86_BR.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/PT/Q269862_W2K_SP2_x86_PT.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/RU/Q269862_W2K_SP2_x86_RU.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/ES/Q269862_W2K_SP2_x86_ES.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/SV/Q269862_W2K_SP2_x86_SV.EXE)
Collapse this image ![]()
(http://download.microsoft.com/download/win2000platform/Patch/q269862/NT5/TR/Q269862_W2K_SP2_x86_TR.EXE)
119591 Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
The English version of this fix should have the
following file attributes or later:
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Date Time Version Size File name ----------------------------------------------------- 08-09-2000 1:02pm 5.0.2195.2103 357,136 W3svc.dll Microsoft Windows NT Server version 4.0, Terminal Server EditionTo resolve this problem, obtain the Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (SRP). For more information about the SRP, click the following article number to view the article in the Microsoft Knowledge Base:317636
(http://support.microsoft.com/kb/317636/
)
Windows NT Server 4.0, Terminal
Server Edition, Security Rollup Package
StatusMicrosoft has confirmed that this is a problem in Internet
Information Services 5.0 and Internet Information Server 4.0.
More information Additional information about this issue is available from
the following Microsoft Web site: http://www.microsoft.com/technet/security/bulletin/MS00-057.mspx You can find frequently asked questions about this vulnerability
at the following Microsoft Web site:
(http://www.microsoft.com/technet/security/bulletin/MS00-057.mspx)
http://www.microsoft.com/technet/security/bulletin/fq00-057.mspx
(http://www.microsoft.com/technet/security/bulletin/fq00-057.mspx)
PropertiesArticle ID: 269862 - Last Review: September 4, 2012 - Revision: 9.0
|



Back to the top








