<> Trend Micro, Inc. June 6, 2006 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Trend Micro(TM) OfficeScan(TM) Corporate Edition 7.3 Hot Fix - Build 1089 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ NOTICE: This hot fix was developed as a workaround or solution to a customer-reported problem. As such, this hot fix has received limited testing and has not been certified as an official product update. Consequently, THIS HOT FIX IS PROVIDED "AS IS". TREND MICRO MAKES NO WARRANTY OR PROMISE ABOUT THE OPERATION OR PERFORMANCE OF THIS HOT FIX NOR DOES IT WARRANT THAT THIS HOT FIX IS ERROR FREE. TO THE FULLEST EXTENT PERMITTED BY LAW, TREND MICRO DISCLAIMS ALL IMPLIED AND STATUTORY WARRANTIES, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY, NONINFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE. Contents =================================================================== 1. Overview of This Hot Fix Release 1.1 Files Included in This Release 2. What's New 3. Documentation Set 4. System Requirements 5. Installation 6. Post-Installation Configuration 7. Known Issues 8. Release History 9. Contact Information 10. About Trend Micro 11. License Agreement =================================================================== 1. Overview of This Hot Fix Release ======================================================================== The OfficeScan server's "CgiRemoteInstall.exe " component located in "\PCCSRV\Web_console\RemoteInstallCGI\CgiRemoteInstall.exe " may have a buffer overflows vulnerability. When this vulnerability is exploited, it is possible to execute codes on the OfficeScan server. This hot fix resolves this issue. 1.1 Files Included in This Release ===================================================================== Module Filename Build No. --------------- --------- CgiRemoteInstall.exe 7.3.0.1089 2. What's New ======================================================================== After applying this hot fix, the OfficeScan server will be able to prevent buffer overflows from happening. 3. Documentation Set ======================================================================== o Readme.txt -- basic installation, known issues, release history and contact information Electronic versions of the printed manuals are available at: http://www.trendmicro.com/download 4. System Requirements ======================================================================== There are no special requirements for installing this hot fix. 5. Installation ======================================================================== To install this hot fix: 1. Copy the hot fix executable file to a temporary folder (for example, "C:\temp"). 2. Double-click the file. The modules are automatically copied to the correct destination. Rollback Procedure ================== This hot fix installation package automatically rolls back the OfficeScan server to its original configuration if there are problems during installation. If you encounter problems after installation, do a manual rollback. To manually roll back to the original configuration: 1. Locate the backup folder that the hot fix package created in the "\PCCSRV\Backup\Hotfix_B1089" directory. 2. Copy the backup files to the original folders. Note: Register online with Trend Micro within 30 days of installation to continue downloading new pattern files and product updates from the Trend Micro Web site. Register during installation or online at: http://olr.trendmicro.com/ 6. Post-Installation Configuration ======================================================================== No post-installation steps are required. Note: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing this hot fix. 7. Known Issues ======================================================================== There are no known issues for this hot fix release. 8. Release History ======================================================================== Visit the following Web site for more information about updates to this product: http://www.trendmicro.com/download 9. Contact Information ======================================================================== A license to the Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, Maintenance must be renewed on an annual basis at Trend Micro's then-current Maintenance fees. You can contact Trend Micro via fax, phone, and email, or visit us at: http://www.trendmicro.com Evaluation copies of Trend Micro products can be downloaded from our Web site. Global Mailing Address/Telephone numbers ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For global contact information in the Asia/Pacific region, Australia and New Zealand, Europe, Latin America, and Canada, refer to: http://www.trendmicro.com/en/about/overview.htm The Trend Micro "About Us" screen displays. Click the appropriate link in the "Contact Us" section of the screen. Note: This information is subject to change without notice. 10. About Trend Micro ======================================================================== Trend Micro, Inc. provides virus protection, anti-spam, and content-filtering security products and services. Trend Micro allows companies worldwide to stop viruses and other malicious code from a central point before they can reach the desktop. Copyright 2006, Trend Micro Incorporated. All rights reserved. Trend Micro, the t-ball logo, and OfficeScan are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other product or company names may be trademarks or registered trademarks of their owners. 11. License Agreement ======================================================================== Information about your license agreement with Trend Micro can be viewed at: http://www.trendmicro.com/en/purchase/license/ Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Getting Started Guide or Administrator's Guide