MS13-007: Vulnerability in Open Data Protocol could allow denial of service: January 8, 2013


Introduction


Microsoft has released the security bulletin MS13-007. You can view the complete security bulletin by going to one of the following Microsoft websites:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More Information


Known issues and additional information about this update

The default Replace canonical function could allow for a denial of service attack. Therefore, this security update disables the Replace canonical function. We recommend that you leave this functionality disabled unless other mitigations are used. For example, using authenticated access to the service or using a provider that is not vulnerable to nested Replace as an attack vector may reduce the risk of a denial of service attack. If you use other mitigations, you can restore Replace functionality by setting enable="true" in a configuration file, as shown in the following XML code example. It can also be restored in service code by setting the enable property to true in the DataServicesReplaceFunctionFeature class.
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<configSections>
<sectionGroup name="wcfDataServices" type="System.Data.Services.Configuration.DataServicesSectionGroup">
<section name="features" type="System.Data.Services.Configuration.DataServicesFeaturesSection" />
</sectionGroup>
</configSections>
<wcfDataServices>
<features>
<replaceFunction enable="true" />
</features>
</wcfDataServices>
</configuration>


The following articles contain additional information about this update as it relates to individual product versions. The articles may contain information that is specific to the individual updates such as download URL, prerequisites, and command-line switches.


Microsoft .NET Framework 4
  • 2736428  MS13-007: Description of the security update for the .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: January 8, 2013

Microsoft .NET Framework 3.5.1
  • 2736422 MS13-007: Description of the security update for the .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1: January 8, 2013
  • 2736418 MS13-007: Description of the security update for the .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2: January 8, 2013

Microsoft .NET Framework 3.5
  • 2736693 MS13-007: Description of the security update for the .NET Framework 3.5 on Windows 8, Windows RT, and Windows Server 2012: January 8, 2013
Microsoft .NET Framework 3.5 Service Pack 1
  • 2736416  MS13-007: Description of the security update for the .NET Framework 3.5 Service Pack 1 on Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008: January 8, 2013
Microsoft Management OData IIS Extension
  • 2753596 MS13-007: Description of the security update for the Management OData IIS Extension on Windows Server 2012: January 8, 2013

Update replacement information

Update replacement information for each specific update can be found in the Knowledge Base articles that correspond to this update.