main

Security Patch: Multiple UNC Provider Buffer Overflow Vulnerability

me101   on 05 April 2002 - 02:55 · 6 comments & 265 views

Advertisement (Why?)
Microsoft has released a patch that resolves the "Unchecked buffer in the Multiple UNC Provider" security vulnerability in Windows XP.

The vulnerability results because of a flaw in the Multiple UNC (uniform naming convention) Provider (MUP), which is a network file system resource locator that runs in kernel-mode memory in Windows.

Download now to prevent a malicious user from causing your computer to restart or to run unauthorized programs.

Requirements: Windows XP Home / Pro

News source: Windows XP Security Patch: Multiple UNC Provider Buffer Overflow Vulnerability
View: Microsoft Security Bulletin - MS02-017 or Microsoft KB article Q311967 (Not available yet!)
Download: Q311967_WXP_SP1_x86_ENU.exe (253kb, 2nd April 2002)

ahodes1 has posted this story in our forum aswell, thanks for contributing to our community ;)


The software is targeted towards large enterprise customers which use PDAs and must protect the data contained in those devices, such as government agencies and hospitals. For example, nurses at a hospital could have patient records uploaded to their Microdrive overnight, and then transferred via the Microdrive from a central PC to their PDA when they arrive in the morning, providing them with a detailed list of patient information for their daily rounds. U.S. federal regulations require that personal information stored by health-care providers be secured.

PDASecure can encrypt some or all of a user's files by converting the files into ciphertext, which is unreadable unless unlocked through a username and password, the company said. The encryption process was derived from a military-grade security algorithm developed by the company, Shahbazi said.

The software works on devices running Palmsource Inc.'s Palm OS, and Microsoft Corp.'s Pocket PC and Windows CE operating systems, said Shahbazi. A version for Research in Motion Ltd.'s Blackberry devices will be released by the end of the month, he said.

PDASecure is currently available worldwide. Large enterprises will pay US$79 for a single license and $999 for the server-side software package. Single users can buy the software to encrypt their personal Microdrives for $29.99, the company said.

Post a comment · Send to friend Comments · There are 6 additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)