FP97: Security Patch for FrontPage Personal Web ServerID: q217765
|
If you use FrontPage Personal Web Server 1.0 (Vhttpd32.exe version 2.0.2.xxxx) on Microsoft Windows 95 or Windows 98 operating systems, your web is vulnerable to unauthorized users accessing your files using a specific non-standard URL. The unauthorized users would have to know the exact file name to access it.
If you are using FrontPage Personal Web Server on Microsoft Windows NT, you are not affected.
Most users of Microsoft FrontPage are not affected as the FrontPage Personal Web Server is available on the FrontPage CD, but was only installed with FrontPage 1.1. Subsequent versions of FrontPage installed Microsoft Personal Web Server 2.0, which is not affected by this issue.
This vulnerability involves the ability of a malicious user to bypass the server's normal file access controls by typing a non-standard URL. The file must be specifically requested by name, so the malicious user would need to already know the name of the file, or correctly guess it. The vulnerability only affects users that host their own Web site with FrontPage Personal Web Server 1.0 (vhttpd32.exe version 2.0.2.xxxx).
http://www.microsoft.com/windows/ie/pws/default.htmYou may download the patch from the following Microsoft Support Site:
http://support.microsoft.com/download/support/mslfiles/Pwssecup.exe
http://officeupdate.microsoft.com/isapi/goftp.asp?TARGET=/products/frontpage/fp98ext_x86_enu.exe
PWSRoot=c:\FrontPage Webs
http://premium.officeupdate.microsoft.com/download/officeupdate/fppws98.exe
For more information about this vulnerability, please see the following Microsoft Web site:
http://www.microsoft.com/security/bulletins/ms99-010.aspFor additional security related information about Microsoft products, please visit the Web site at:
http://www.microsoft.com/security
Additional query words: front page fix add-on add on update
Keywords : kbdta
Version : WINDOWS:97
Platform : WINDOWS
Issue type :
Last Reviewed: July 1, 1999