Windows 2000 Kerberos LSA Memory Leak/DoS Vulnerability
BID:2707
Info
Windows 2000 Kerberos LSA Memory Leak/DoS Vulnerability
| Bugtraq ID: | 2707 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2001 12:00AM |
| Updated: | May 08 2001 12:00AM |
| Credit: | Discovered by Peter Grundl <[email protected]> and posted in Microsoft Security Bulletin MS01-024 on May 8th, 2001. |
| Vulnerable: |
Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Windows 2000 Kerberos LSA Memory Leak/DoS Vulnerability
Kerberos is an authentication service that issues a ticket when a user logs on to a particular server. It then passes the ticket on to other servers so that the user does not have to log on seperately in each domain.
By repeatedly connecting to the Kerberos service and then disconnecting before the socket is read, a denial of service attack may be effected.
Kerberos is an authentication service that issues a ticket when a user logs on to a particular server. It then passes the ticket on to other servers so that the user does not have to log on seperately in each domain.
By repeatedly connecting to the Kerberos service and then disconnecting before the socket is read, a denial of service attack may be effected.
Exploit / POC
Windows 2000 Kerberos LSA Memory Leak/DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Windows 2000 Kerberos LSA Memory Leak/DoS Vulnerability
Solution:
Microsoft has created a patch to address this issue:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29537
There is a language selection page and relevant information on installing the patch.
Solution:
Microsoft has created a patch to address this issue:
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29537
There is a language selection page and relevant information on installing the patch.
References
Windows 2000 Kerberos LSA Memory Leak/DoS Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-024 (Microsoft)