This patch is a cumulative patch that includes the functionality of all security patches released for IIS 4.0 since Windows NT 4.0 Service Pack 6a, and all security patches released to date for IIS 5.0 and 5.1. A complete listing of the patches superseded by this patch is provided below, in the section titled “Additional information about this patch”. Before applying the patch, system administrators should take note of the caveats discussed in the same section.
In addition, the patch causes 5.0 and 5.1 to change how frequently the socket backlog list – which, when all connections on a server are allocated, holds the list of pending connection requests – is purged. The patch changes IIS to purge the list more frequently in order to make it more resilient to flooding attacks. The backlog monitoring feature is not present in IIS 4.0.
|