05 Jul 2002
Microsoft has started to release patches for its patches.
A recent security bulletin issued by the Redmond giant announced that a fix released on 12 June, which addressed a flaw in the Remote Access Service (RAS) phone book in several versions of Windows, can stop users from making virtual private network connections.
A new patch has now been released to fix the problem caused by the first patch.
RAS provides dial-up connections between computers and networks over phone lines. It is delivered as a native system service in Windows NT 4.0, 2000 and XP, and is included in a separately downloadable Routing and RAS for NT 4.0.
All of these implementations include a RAS phonebook which is used to store information about security, telephone numbers and network settings used to dial remote systems.
According to the Microsoft warning a phonebook value is not properly checked, and is susceptible to a buffer overrun.
The overrun could be exploited to cause a system failure, or run code on the system with Local System privileges.
The revised patch can be found at the Microsoft Download Centre and will be soon available through Windows Update.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Sales Consultant - Data Centre, Colocation, Hosting...
Senior Interaction Designer (User Experience, UCD, Interactive...
Information Architecture / IA / User Experience / UX...
Sales Consultant A rapidly expanding independent managed...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?