CERT mailing list archives

Current Activity - Microsoft Releases Security Advisory 2416728


From: Current Activity <us-cert () us-cert gov>
Date: Mon, 27 Sep 2010 10:07:11 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Microsoft Releases Security Advisory 2416728

Original release date: September 20, 2010 at 3:15 pm
Last revised: September 27, 2010 at 9:32 am


Microsoft has released a security advisory to alert users of a
vulnerability affecting ASP.NET. Exploitation of this vulnerability
may allow an attacker to obtain sensitive information or tamper with
data.

US-CERT encourages administrators to review Microsoft security
advisory 2416728 and apply any necessary workarounds until a fix is
released by the vendor.

Update: Microsoft has indicated that this vulnerability affects all
applications that rely on the ASP.NET platform. Microsoft has also
updated the security advisory to include additional workaround
details. The Microsoft SharePoint Team has updated its blog entry
"Security Advisory 2416728 (Vulnerability in ASP.NET) and SharePoint"
to assist users in how to mitigate these risks in SharePoint.

US-CERT will provide additional information as it becomes available.

Relevant Url(s):
<http://blogs.msdn.com/b/sharepoint/archive/2010/09/21/security-advisory-2416728-vulnerability-in-asp-net-and-sharepoint.aspx>

<https://www.microsoft.com/technet/security/advisory/2416728.mspx>

====
This entry is available at
http://www.us-cert.gov/current/index.html#microsoft_releases_security_advisory_2416728

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBTKCk6z6pPKYJORa3AQL+hQf9H+MN8LNeQcFgP9Aj98Ncp1FFr90Kgreg
xB5D+lFFsQNSw3ODkm+Q1PbTizA/Zx34ky/nR7+IyQJNe//GxbBFXJwuwTCT81wy
i5uqVbJjOe/wL5AHvk5Uwj1Njx69Dw8URKWA6fw0q6dNwxIVuuDk/H4HAnLNU+Gt
nbDKnrUjDCUrPzf4/SRgbCWwQB9jPisDGMIeBja2h1PyQhZs74ZIiDazSPkaFhOq
jzd/DlYQqcXojJwA5w+Ue8JtEhSxhS/ar9pw1f1xBsL8+QMdOXPp+etFzFs+RoLP
RdiqPlipTU3yxXloQutVXfvK09bswuJbx44SqLc3tvZ1+OCh0mke/Q==
=DdCi
-----END PGP SIGNATURE-----


Current thread: