File: 2258.txt

package info (click to toggle)
snort 2.9.7.0-5
  • links: PTS, VCS
  • area: main
  • in suites: stretch
  • size: 55,000 kB
  • ctags: 38,464
  • sloc: ansic: 266,667; sh: 12,508; makefile: 2,908; yacc: 497; perl: 496; lex: 261; sed: 14
file content (78 lines) | stat: -rw-r--r-- 1,944 bytes parent folder | download | duplicates (16)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
Rule:

--
Sid:

--
Summary:
This event is generated when an attempt is made to exploit a known
vulnerability in the Microsoft Windows Messenger service.

--
Impact:
Serious. Denial of Service (DoS), execution of arbitrary code is
possible.

--
Detailed Information:
Due to improper length validation in the Microsoft Windows Messenger
service, it may be possible for an attacker to overwrite portions of
memory. This can result in the attacker being presented with the
opportunity to execute code of their choosing. Under some circumstances
a Denial of Service condition may be possible against the target host.

Specifically, this vulnerability may present the attacker with the
opportunity to execute code with the privileges of the local system
account with full access to all resources on the target host.

--
Affected Systems:
	Microsoft Windows NT Workstation 4.0, Service Pack 6a
	Microsoft Windows NT Server 4.0, Service Pack 6a
	Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
	Microsoft Windows 2000, Service Pack 2, Service Pack 3, Service Pack 4
	Microsoft Windows XP Gold, Service Pack 1
	Microsoft Windows XP 64-bit Edition
	Microsoft Windows XP 64-bit Edition Version 2003
	Microsoft Windows Server 2003
	Microsoft Windows Server 2003 64-bit Edition

--
Attack Scenarios:
The attacker may use one of the available exploits to target a
vulnerable host.

--
Ease of Attack:
Simple. Exploit code exists.

--
False Positives:
None known.

--
False Negatives:
None known

--
Corrective Action:
Apply the appropriate vendor supplied patches and service packs.

Disable the Windows messenger service

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

CERT:
http://www.kb.cert.org/vuls/id/575892

Microsoft:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-043.asp

--