FrontPage Server Extensions Image Map Files Expose Security Vulnerability (260267)
The information in this article applies to:
- Microsoft FrontPage 98 for Windows
- Microsoft FrontPage 97 for Windows
This article was previously published under Q260267 SYMPTOMS
The FrontPage 97 and 98 Server Extensions include two image map files, Htimage.exe and Imagemap.exe, which are server-side NCSA and CERN compliant components, that are used to support server-side image maps.
These files were originally provided to support image maps with Netscape and Internet Explorer versions 1.0 and 2.0. However, both files contain unchecked buffers that may be used to run arbitrary code. These files expose security vulnerabilities, which can result in buffer overruns, exploits of cross-site scripting, and access to drive path and file information.
NOTE: This problem does not occur in the FrontPage 2000 Server Extensions.
RESOLUTION
To eliminate this vulnerability, customers who are hosting Web sites using any of the affected products need to delete all copies of the Htimage.exe and Imagemap.exe files from their servers. The only functionality lost by deleting these files is the ability to support image mapping for Web site visitors using legacy browser products.
This is a short-term fix, because it is possible that FrontPage customers may unknowingly publish the files to the server in their normal course of updating their Webs. STATUSMicrosoft has confirmed that this is a problem in Microsoft FrontPage 97 and 98 for Windows.
Modification Type: | Major | Last Reviewed: | 10/30/2003 |
---|
Keywords: | kbbug kbpending KB260267 |
---|
|