|
Microsoft Windows NT Denial of Service
|
|
Secunia Advisory:
|
SA9337
|
|
|
Release Date:
|
2003-07-24
|
|
Last Update:
|
2003-08-14
|
|
Popularity:
|
7,797 views
|
|
|
Critical:
|
 Not critical
|
|
Impact:
|
DoS
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Microsoft Windows NT 4.0 Server Microsoft Windows NT 4.0 Server, Terminal Server Edition
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2003-0525
|
|
Description: A vulnerability has been identified in Microsoft Windows NT which possibly could allow malicious users to cause certain applications to fail.
The problem is that the file management function may free memory that it doesn't own if it receives a malicious request. This does not affect the operating system but only the application which called the file management function.
Microsoft did not provide any example of an application or configuration which is vulnerable to this issue, but stated that this possibly could affect Internet Information Server 4.0 in a non-default configuration.
Solution: Patches are avilable:
Microsoft Windows NT 4.0 Server:
http://microsoft.com/downloads/detail...-851F-FFBE2490B901&displaylang=en
Microsoft Windows NT 4.0 Terminal Server Edition:
http://microsoft.com/downloads/detail...-B142-F505BB208797&displaylang=en
Provided and/or discovered by: Jeremy Rauch, @stake
Changelog: 2003-07-30 Microsoft has issued a hotfix due to problems with the patches on certain configurations.
2003-08-13 New patches released to fix the problem with RRAS configurations.
Original Advisory: http://www.microsoft.com/technet/security/bulletin/MS03-029.asp
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|