Microsoft Active Directory Zero Page Length Query Vulnerability
BID:4804
Info
Microsoft Active Directory Zero Page Length Query Vulnerability
| Bugtraq ID: | 4804 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2002 12:00AM |
| Updated: | May 23 2002 12:00AM |
| Credit: | Credited to Jonathan Lamberson <[email protected]>. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Active Directory Zero Page Length Query Vulnerability
Microsoft Active Directory is reportedly vulnerable to a query that will result in Active Directory to cease responding.
The vulnerability has been reported for querying Active Directory servers using Kerberos V authentication via GSS-API.
A LDAP client is able to specify the number of entries to be retrieved by setting a page length to a smaller number. The reported vulnerability occurs when the page length value is set to zero and the client makes a large request.
Such a request will cause the vulnerable Active Directory server to hang causing a denial of service to occur.
Microsoft Active Directory is reportedly vulnerable to a query that will result in Active Directory to cease responding.
The vulnerability has been reported for querying Active Directory servers using Kerberos V authentication via GSS-API.
A LDAP client is able to specify the number of entries to be retrieved by setting a page length to a smaller number. The reported vulnerability occurs when the page length value is set to zero and the client makes a large request.
Such a request will cause the vulnerable Active Directory server to hang causing a denial of service to occur.
Exploit / POC
Microsoft Active Directory Zero Page Length Query Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Active Directory Zero Page Length Query Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.