Select the product you need help with
MS13-007: Vulnerability in Open Data Protocol could allow denial of service: January 8, 2013Article ID: 2769327 Applies toCollapse this image ![]()
Collapse this image ![]() On This PageIntroductionMicrosoft has released the security bulletin MS13-007. You can view the complete security bulletin by going to one of the following Microsoft websites:
How to obtain help and support for this security updateHelp installing updates: Support for Microsoft Update
(http://support.microsoft.com/ph/6527)
Security solutions for IT professionals: TechNet Security Troubleshooting and Support
(http://technet.microsoft.com/security/bb980617.aspx)
Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
(http://support.microsoft.com/contactus/cu_sc_virsec_master)
Local support according to your country: International Support
(http://support.microsoft.com/common/international.aspx)
More informationKnown issues and additional information about this updateThe default Replace canonical function could allow for a denial of service attack. Therefore, this security update disables the Replace canonical function. We recommend that you leave this functionality disabled unless other mitigations are used. For example, using authenticated access to the service or using a provider that is not vulnerable to nested Replace as an attack vector may reduce the risk of a denial of service attack. If you use other mitigations, you can restore Replace functionality by setting enable="true" in a configuration file, as shown in the following XML code example. It can also be restored in service code by setting the enable property to true in the DataServicesReplaceFunctionFeature
(http://msdn.microsoft.com/en-us/library/system.data.services.configuration.dataservicesreplacefunctionfeature.aspx)
class.
The following articles contain additional information about this update as it relates to individual product versions. The articles may contain information that is specific to the individual updates such as download URL, prerequisites, and command-line switches. Microsoft .NET Framework 4
Microsoft .NET Framework 3.5.1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5 Service Pack 1
Microsoft Management OData IIS Extension
File hash informationCollapse this image ![]() Collapse this table
Collapse this image ![]() Update replacement informationUpdate replacement information for each specific update can be found in the Knowledge Base articles that correspond to this update.PropertiesArticle ID: 2769327 - Last Review: January 8, 2013 - Revision: 1.0
| Article Translations
|




Back to the top








