-----BEGIN PGP SIGNED MESSAGE-----

===========================================================================
             AUSCERT External Security Bulletin Redistribution

    ESB-2001.251 -- Microsoft Security Bulletin MS00-077 (version 2.0)
      Patch Available for "NetMeeting Desktop Sharing" Vulnerability
                               25 June 2001

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:                Netmeeting
Vendor:                 Microsoft
Operating System:       Windows
Impact:                 Denial of Service
Access Required:        Remote

Ref:                    ESB-200.292

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----

- - ----------------------------------------------------------------------
Title:      Patch Available for "NetMeeting Desktop Sharing" 
            Vulnerability
Released:   13 October 2000
Revised:    21 June 2001 (version 2.0)
Software:   Netmeeting
Impact:     Denial of service
Bulletin:   MS00-077

Microsoft encourages customers to review the Security Bulletin at: 
http://www.microsoft.com/technet/security/bulletin/MS00-077.asp.
- - ----------------------------------------------------------------------

Reason for Revision:
====================
A new variant of the originally reported vulnerability has been
found.  
The patch has been updated to address both the original and new 
variants.

Issue:
======
A remote denial of service vulnerability has been discovered in a 
component of Microsoft(r) NetMeeting. The denial of service can occur
when a malicious client sends a particular malformed string to a port
which the NetMeeting service is listening on and with Remote Desktop 
Sharing enabled. 

Although the NetMeeting application is provided as part of Windows(r)
2000 products, the application and affected component is not enabled
by 
default, and customers who have not enabled it would not be at risk 
from this vulnerability. 

Mitigating Factors:
====================
 - NetMeeting is not enabled by default on either Windows 2000 or
   Windows NT(r) 4.0.  
 - The vulnerability could not be used for any broader attack - that 
   is, it could not be used to compromise data within a Netmeeting 
session
   or usurp administrative control of a remote desktop session.

Patch Availability:
===================
 - A patch is available to fix this vulnerability. Please read the 
   Security Bulletin
   http://www.microsoft.com/technet/security/bulletin/ms00-077.asp
   for information on obtaining this patch.

Acknowledgment:
===============
 - Peter Grundl

- - ---------------------------------------------------------------------

THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED 
"AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL 
WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF 
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT
SHALL 
MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES 
WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL,
LOSS 
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH
DAMAGES. 
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY
NOT 
APPLY.




- -----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.3

iQEVAwUBOzKujI0ZSRQxA/UrAQEJ/QgAnP0Kx9rxNVrMYyzAndqQRbC1Svu40nOu
KRwmkGGwusnR7w1FWuDFiWmqkJ1+Kditqhnm0EOGoM8qAZ6p676I46+l1H9/7fiS
Xfb+WwaxU/WiHAwdqaY+Pcbka0dhPcFgwiI5K9XrzACLGSfgUBwfGJmkvEDyEDZn
NnLcJeU2ISDPzdKPywYfCeVpifWR5EltvUqjAvWooOwjh6ga9aS1thREJaEocuyM
ydds+cvqYeCYRQCmK7sciLwi5UOwP7eRiz59h3SS7oz3uTTvIr5QkaSd7eOu6M3u
Bj14GZ+DxxfNC40Rv9TU/tpnwi2LjeNdAosaJfTeYiU+epCixuIbJQ==
=QCFG
- -----END PGP SIGNATURE-----



- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content.  The decision to use any or all of this information is
the responsibility of each user or organisation, and should be done so in
accordance with site policies and procedures.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the original authors to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

	http://www.auscert.org.au/Information/advisories.html

If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security
Teams).

Internet Email: auscert@auscert.org.au
Facsimile:	(07) 3365 7031
Telephone:	(07) 3365 4417 (International: +61 7 3365 4417)
		AusCERT personnel answer during Queensland business hours
		which are GMT+10:00 (AEST).
		On call after hours for emergencies.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key

iQCVAwUBOzdS0Ch9+71yA2DNAQENqgQAkNvZYjrV0UDogQ2sNpQRYshxpFYmPv3J
4YS3gz54cgrVhtxwm598wln9YNyLmgWmQCla5qoJ1+1nhWRaxdSAIEUJf0eWLacD
O+3rvfypHYbNXWXzkuUb4ejoIA8HlSfReBBCvSXSRfaJbFKrgN42wO2PMPpVdid0
hvAnY6SjjQ0=
=ZXxw
-----END PGP SIGNATURE-----