Microsoft KB Archive/922770

= MS06-056: Vulnerability in ASP.NET 2.0 could allow for information disclosure =

Article ID: 922770

Article Last Modified on 12/3/2007

-

APPLIES TO


 * Microsoft .NET Framework 2.0
 * Microsoft Windows Server 2003 Service Pack 1
 * Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
 * Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
 * Microsoft Windows Server 2003, Standard Edition (32-bit x86)
 * Microsoft Windows Server 2003, Web Edition
 * Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
 * Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
 * Microsoft Windows Server 2003, Standard x64 Edition
 * Microsoft Windows Server 2003, Enterprise x64 Edition
 * Microsoft Windows Server 2003, Datacenter x64 Edition
 * Microsoft Windows Server 2003 R2 Standard x64 Edition
 * Microsoft Windows Server 2003 R2 Enterprise x64 Edition
 * Microsoft Windows Server 2003 R2 Datacenter x64 Edition
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Datacenter Server
 * Microsoft Windows 2000 Professional Edition
 * Microsoft Windows 2000 Service Pack 4
 * Microsoft Windows XP Service Pack 1
 * Microsoft Windows XP Service Pack 2
 * Microsoft Windows XP Professional x64 Edition
 * Microsoft Windows XP Media Center Edition 2002

-



Microsoft has released security bulletin MS06-056. The security bulletin contains all the relevant information about the security update. This information includes file manifest information and deployment options. To view the complete security bulletin, visit one of the following Microsoft Web sites:  Home users:

http://www.microsoft.com/athome/security/update/bulletins/200610.mspx

 IT professionals:

http://www.microsoft.com/technet/security/bulletin/ms06-056.mspx





Known issues
 To install this security update, you must have Microsoft Windows Installer 3.1 installed on your computer. To obtain the latest Windows Installer for your computer, visit the following Microsoft Web site:

http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c

 For more information about installation issues with Microsoft .NET Framework 2.0, click the following article number to view the article in the Microsoft Knowledge Base:

923100 When you try to install a security update for the .NET Framework 2.0, the computer may stop responding, or you may receive a &quot;0x643&quot; error code

 For more information about installation issues with x64-based versions of Microsoft Windows Server 2003, click the following article number to view the article in the Microsoft Knowledge Base:

923101 Error message when you try to install a security update for the .NET Framework 2.0 on a computer that is running Windows Server 2003 x64 Edition: &quot;Error 1324. The folder 'Program Files' contains an invalid character&quot;

 For more information about issues after you install an update for the .NET Framework 2.0, click the following article number to view the article in the Microsoft Knowledge Base:

929110 A file system that was case sensitive becomes case insensitive after you install an update for the .NET Framework 2.0

</li></ul>

For more information about the security update for the .NET Framework 2.0 ASP.NET development platform, visit the following Microsoft Web site:

http://www.microsoft.com/technet/security/bulletin/ms06-056.mspx

.

Additional query words: update security_patch security_update security bug flaw vulnerability malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service DoS TSE WinNT Win2000

Keywords: kbwinserv2003presp2fix kbwinxppresp3fix kbwin2000presp5fix kbexpertisebeginner kbqfe kbsecurity kbsecbulletin kbsecvulnerability kbbug kbfix kbpubtypekc KB922770

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.