----- Original Message -----
> Although it would be great if everyone running Windows 2000 installs this
> patch, it would also be great to know *why* it is needed.  Right now,
there
> is just a rumor that it goes beyond IIS/WebDAV.

   According to  the paper at
  http://www.nextgenss.com/papers/ms03-007-ntdll.pdf

  ntdll.dll is the core culprit.  Since it is used by so many applications
without limit checking, any of those applications might in theory pass
unchecked buffers to ntdll.dll.   Extrapolating, this *could* mean that 3rd
party applications such as Webmail are vulnerable.   Note that there is no
reason to believe that Webmail is vulnerable to this type of attack; just
that it's an example of a reason to install the patch even if you have
already disabled WebDAV.



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to