----- Original Message ----- > Although it would be great if everyone running Windows 2000 installs this > patch, it would also be great to know *why* it is needed. Right now, there > is just a rumor that it goes beyond IIS/WebDAV.
According to the paper at http://www.nextgenss.com/papers/ms03-007-ntdll.pdf ntdll.dll is the core culprit. Since it is used by so many applications without limit checking, any of those applications might in theory pass unchecked buffers to ntdll.dll. Extrapolating, this *could* mean that 3rd party applications such as Webmail are vulnerable. Note that there is no reason to believe that Webmail is vulnerable to this type of attack; just that it's an example of a reason to install the patch even if you have already disabled WebDAV. To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
