Microsoft Index Server Buffer Overflow Vulnerability
BID:2709
Info
Microsoft Index Server Buffer Overflow Vulnerability
| Bugtraq ID: | 2709 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2001 12:00AM |
| Updated: | May 11 2001 12:00AM |
| Credit: | Discovered by David Litchfield of @Stake and posted in a Microsoft Security Bulletin MS01-025. |
| Vulnerable: |
Microsoft Index Server 2.0 |
| Not Vulnerable: |
Microsoft Indexing Services for Windows 2000 |
Discussion
Microsoft Index Server Buffer Overflow Vulnerability
Windows Index Server ships with Windows NT 4.0 Option Pack and contains an unchecked buffer in the handling of user search requests. A maliciously crafted search request could allow the execution of arbitrary code on the host.
Windows Index Server ships with Windows NT 4.0 Option Pack and contains an unchecked buffer in the handling of user search requests. A maliciously crafted search request could allow the execution of arbitrary code on the host.
Exploit / POC
Microsoft Index Server Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Index Server Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch which addresses this issue:
Microsoft Index Server 2.0
Solution:
Microsoft has released a patch which addresses this issue:
Microsoft Index Server 2.0
References
Microsoft Index Server Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-025 (Microsoft)