Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
BID:11380
Info
Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
| Bugtraq ID: | 11380 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0569 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; BindView Corporation is credited with disclosure. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 alpha Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows NT 4.0 SP6a alpha Microsoft Windows NT 4.0 SP6a Microsoft Windows NT 4.0 SP6 alpha Microsoft Windows NT 4.0 SP6 Microsoft Windows NT 4.0 SP5 alpha Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 alpha Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 alpha Microsoft Windows NT 4.0 SP3 alpha Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 alpha Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 alpha Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 alpha Microsoft Windows NT 4.0 Microsoft Windows ME Microsoft Windows 98SE Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya IP600 Media Servers R9 Avaya IP600 Media Servers R8 Avaya IP600 Media Servers R7 Avaya IP600 Media Servers R6 Avaya IP600 Media Servers R12 Avaya IP600 Media Servers R11 Avaya IP600 Media Servers R10 Avaya IP600 Media Servers Avaya DefinityOne Media Servers R9 Avaya DefinityOne Media Servers R8 Avaya DefinityOne Media Servers R7 Avaya DefinityOne Media Servers R6 Avaya DefinityOne Media Servers R12 Avaya DefinityOne Media Servers R11 Avaya DefinityOne Media Servers R10 Avaya DefinityOne Media Servers |
| Not Vulnerable: | |
Discussion
Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
Microsoft RPC Runtime Library is affected by a remote denial of service and information disclosure vulnerability. This issue is due to a failure of the library to properly handle exceptional network traffic.
An attacker may leverage this issue to disclose potentially sensitive information and to cause the affected application to crash, denying service to legitimate users.
Microsoft RPC Runtime Library is affected by a remote denial of service and information disclosure vulnerability. This issue is due to a failure of the library to properly handle exceptional network traffic.
An attacker may leverage this issue to disclose potentially sensitive information and to cause the affected application to crash, denying service to legitimate users.
Exploit / POC
Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
A proof of concept for this issue is known to exist, although it is not currently in public circulation.
A proof of concept for this issue is known to exist, although it is not currently in public circulation.
Solution / Fix
Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
Solution:
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Customers are advised to follow Microsoft's guidance for applying patches. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=203487&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft has released a bulletin that includes fixes to address this issue for supported versions of the operating system.
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT 4.0 SP6a
Solution:
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Customers are advised to follow Microsoft's guidance for applying patches. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=203487&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft has released a bulletin that includes fixes to address this issue for supported versions of the operating system.
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB873350)
http://download.microsoft.com/download/1/6/1/16145263-1a0d-4421-a6ac-1 12e200cf804/WindowsNT4Server-KB873350-x86-ENU.exe
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Security Update for Windows NT Server 4.0, Terminal Server Edition (KB873350)
http://download.microsoft.com/download/5/c/9/5c972f06-c43f-404d-ad9d-4 4c33aa88f25/WindowsNT4TerminalServer-KB873350-x86-ENU.exe
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB873350)
http://download.microsoft.com/download/1/6/1/16145263-1a0d-4421-a6ac-1 12e200cf804/WindowsNT4Server-KB873350-x86-ENU.exe
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB873350)
http://download.microsoft.com/download/1/6/1/16145263-1a0d-4421-a6ac-1 12e200cf804/WindowsNT4Server-KB873350-x86-ENU.exe
Microsoft Windows NT 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB873350)
http://download.microsoft.com/download/1/6/1/16145263-1a0d-4421-a6ac-1 12e200cf804/WindowsNT4Server-KB873350-x86-ENU.exe
References
Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-029 (Microsoft)
- BindView Advisory: Memory Leak and DoS in NT4 RPC server (advisory
)