OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Alert: Microsoft Security Bulletin (MS98-007) - Exchange Server
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Alert: Microsoft Security Bulletin (MS98-007) - Exchange Server


  • To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
  • Subject: Alert: Microsoft Security Bulletin (MS98-007) - Exchange Server
  • From: Russ <Russ.CooperRC.ON.CA>
  • Date: Sat, 25 Jul 1998 11:03:53 -0400
  • Reply-To: Russ <Russ.CooperRC.ON.CA>
  • Sender: Windows NT BugTraq Mailing List <NTBUGTRAQLISTSERV.NTBUGTRAQ.COM>

Microsoft have released a Security Bulletin
(http://www.microsoft.com/security/bulletins/ms98-007.htm) which covers
a potential Denial of Service vulnerability in Microsoft Exchange Server
v5.0 and v5.5, it does not affect v4.0.

Discovered by the ISS X-Force team, the vulnerabilities can result in
services being stopped. Specifically, an SMTP exploit can result in the
Internet Mail Service failing, and an NNTP exploit could result in the
Server Information Store service failing.

In both cases, services can be restarted and will function correctly
without a reboot, which is a good reason to use one of the many programs
which can detect service stops and restart them automatically. The
bulletin advises the use of Exchange Servers "Server Monitor" feature in
the Exchange Administrator program which can do this.

Each version requires two patches if you use both services (SMTP and
NNTP) and can be found through the bulletin link above.

Cheers,
Russ