FW: New Macromedia Security Zone Bulletins Posted

From: Benjamin Keller (benjaminat_private)
Date: Thu May 09 2002 - 18:31:05 PDT

  • Next message: Roger Safian: "FIRST 2002 reminder"

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    IMPORTANT: 
    
    Several security issues that may affect Macromedia JRun and
    ColdFusion customers have come to our attention recently.
    
    To learn about these new issues and what actions you can
    take to address them, Please visit the Security Zone at the
    Macromedia Web site:
    
    http://www.macromedia.com/security
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    
    MPSB02-01
    
    Macromedia Security Bulletin (MPSB02-01)
    
    Certain DOS reserved filenames may cause ColdFusion to display 
    the physical web root directory when ColdFusion is used with 
    Microsoft IIS.
    
    Originally Posted: May 9, 2002
    
    Summary
    Certain DOS reserved filenames, such as NUL or PRN, can cause 
    ColdFusion to display the path to the web root directory in an 
    error message.
    
    ~~~~~~~
    What Customers Should Do
    
    
    Customers are advised to implement one of the two methods described 
    if disclosure of the IIS web root is a security concern.
    
    
    Revisions
    
    May 9, 2002 - Bulletin first released.
    
    
    ~~~~~~~
    Thank you for your time and consideration on this issue.
    
    Security Response Team,
    Macromedia, Inc.
    
    ~~~~
    P.S.  As a reminder, Macromedia has set up the following
    e-mail address that customers can use to report security
    issues associated with any Macromedia product:
    
    [mailto:secureat_private]
    
    
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Reporting Security Issues 
    Macromedia is committed to addressing security issues and 
    providing customers with the information on how they can 
    protect themselves. If you identify what you believe may be 
    a security issue with a Macromedia product, please send an 
    email to secureat_private We will work to appropriately 
    address and communicate the issue. 
    
    ~~~~~~~
    Receiving Security Bulletins 
    When Macromedia becomes aware of a security issue that we 
    believe significantly affects our products or customers, we 
    will notify customers when appropriate. Typically this notification 
    will be in the form of a security bulletin explaining the issue 
    and the response. Macromedia customers who would like to receive 
    notification of new security bulletins when they are released 
    can sign up for our security notification service. 
    
    For additional information on security issues at Macromedia, 
    please visit the Security Zone at:
    
    http://www.macromedia.com/security
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    THE INFORMATION PROVIDED BY MACROMEDIA IN THIS BULLETIN IS 
    PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MACROMEDIA 
    AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, WHETHER EXPRESS 
    OR IMPLIED OR OTHERWISE, INCLUDING THE WARRANTIES OF MERCHANTABILITY 
    AND FITNESS FOR A PARTICULAR PURPOSE. ALSO, THERE IS NO WARRANTY 
    OF NON-INFRINGEMENT, TITLE OR QUIET ENJOYMENT. (USA ONLY) 
    SOME STATES DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, 
    SO THE ABOVE EXCLUSION MAY NOT APPLY TO YOU. 
    
    IN NO EVENT SHALL MACROMEDIA, INC. OR ITS SUPPLIERS BE LIABLE 
    FOR ANY DAMAGES WHATSOEVER INCLUDING, WITHOUT LIMITATION, DIRECT, 
    INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, COVER, 
    LOSS OF PROFITS, BUSINESS INTERRUPTION OR THE LIKE, OR LOSS OF 
    BUSINESS DAMAGES, BASED ON ANY THEORY OF LIABILITY INCLUDING 
    BREACH OF CONTRACT, BREACH OF WARRANTY, TORT(INCLUDING NEGLIGENCE), 
    PRODUCT LIABILITY OR OTHERWISE, EVEN IF MACROMEDIA, INC. OR ITS 
    SUPPLIERS OR THEIR REPRESENTATIVES HAVE BEEN ADVISED OF THE POSSIBILITY 
    OF SUCH DAMAGES. (USA ONLY) SOME STATES DO NOT ALLOW THE EXCLUSION OR 
    LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, SO 
    THE ABOVE EXCLUSION OR LIMITATION MAY NOT APPLY TO YOU AND YOU MAY 
    ALSO HAVE OTHER LEGAL RIGHTS THAT VARY FROM STATE TO STATE. 
    
    Macromedia reserves the right, from time to time, to update the 
    information in this document with current information.
    



    This archive was generated by hypermail 2b30 : Fri May 10 2002 - 20:25:34 PDT