|
Brought to you by:
Suppliers of:
|
|
|
| |
| The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0. |
| |
Credit:
The information has been provided by Kingcope and Microsoft.
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/MS09-053.mspx
|
| |
Vulnerable Systems:
* IIS 5.0 (FTP Service 5.0)
* IIS 5.1 (FTP Service 5.1)
* IIS 6.0 (FTP Service 6.0)
* IIS 7.0 (FTP Service 6.0)
This security update is rated Important for IIS 5.0; IIS 5.1; IIS 6.0; and FTP Service 6.0 on IIS 7.0.
The security update addresses the vulnerabilities by modifying the way that the FTP Service handles list operations.
Patch Availability:
http://go.microsoft.com/fwlink/?LinkID=40747
CVE Information:
CVE-2009-2521
CVE-2009-3023
|
|
|
|
|