RE: personal web server directory traversal vulnerability patch

From: Dinos Pastos (dinopioat_private)
Date: Thu Jun 14 2001 - 13:58:08 PDT

  • Next message: Brian McKinney: "RE: OpenBSD 2.9,2.8 local root compromise"

    Patch from an Unofficial Source?
    
    I quote from site.
    
    "Patch assembled from Microsoft files by David Raitzer
    david_raitzerat_private, Project Information Management Specialist,
    Cornell International Institute for Food, Agriculture and Development "
    
    This doesnt look right.
    Since Microsoft never developed a patch for PWS after I submited the bug, I
    would advise using a patch from an unknown source.
    
    I am not saying the patch is a fake or that it doesnt work.
    
    Dinos Pastos
    Security Advisor
    InterceptiX Security
    
    ----- Original Message -----
    From: "David Raitzer" <david_raitzerat_private>
    To: <bugtraqat_private>
    Sent: Thursday, June 14, 2001 12:08 AM
    Subject: personal web server directory traversal vulnerability patch
    
    
    > Personal Web Server Users,
    >
    > I assembled an effective patch for the UNICODE directory traversal
    > vulnerability issue in Microsoft Personal Web Server 4.0 for Windows
    95/98,
    > which was noted previously on this list.  It can be downloaded at:
    > http://www.geocities.com/p_w_server/pws_patch/index.htm
    >
    > -David Raitzer
    > _________________________________________________________________
    > Get your FREE download of MSN Explorer at http://explorer.msn.com
    >
    >
    



    This archive was generated by hypermail 2b30 : Fri Jun 15 2001 - 09:55:27 PDT