Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Network + Systems Management
R E V I E W  
PatchLink Helps Keep Windows Closed

  September 2, 2002
  By Patrick Mueller


>> continued from previous page

A Heap of Trouble

TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
PatchLink Corp. PatchLink Update 3.0
arrow
Other Products Reviewed
arrow
Executive Summary
arrow
Why Patch?
arrow
How We Tested
arrow
A Heap of Trouble
arrow
Microsoft's Patch tools: Incomplete
arrow
Report Card

To the left is a single item taken from the mssecure.xml patch database file provided by Microsoft and used by its HFNetChk tool as well as Shavlik Technologies' commercial version, HFNetChkPro Enterprise.

A heap-overflow vulnerability in Microsoft IIS was discovered during the writing of this article, and a patch was released at roughly the same time the vulnerability was announced. By examining the example, you can get an idea of how the tool works. For instance, this security bulletin patch is not included (obviously) in SP1 or SP2 but will presumably be present in SP3. The Q-number as well as a pointer to the patch download location are both included.

More information on the vulnerability can be found at "Microsoft Security Bulletin MS02-028 and "Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow."


start top   How We Tested Microsoft's Patch tools: Incomplete 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers