Microsoft Malformed RPC Packet Buffer Overflow Vulnerability
BID:5879
Info
Microsoft Malformed RPC Packet Buffer Overflow Vulnerability
| Bugtraq ID: | 5879 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1140 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | This vulnerability was first detailed in a Microsoft Security Bulletin. |
| Vulnerable: |
Microsoft Services for Unix 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft Malformed RPC Packet Buffer Overflow Vulnerability
A denial of service vulnerability has been reported for RPC applications built using Microsoft Services for Unix Interix SDK.
This vulnerability is the result of RPC clients transmitting data in variable sized fragments. When RPC servers receive malformed fragments, the buffer overflow condition is triggered resulting in the RPC server failing to respond.
A denial of service vulnerability has been reported for RPC applications built using Microsoft Services for Unix Interix SDK.
This vulnerability is the result of RPC clients transmitting data in variable sized fragments. When RPC servers receive malformed fragments, the buffer overflow condition is triggered resulting in the RPC server failing to respond.
Exploit / POC
Microsoft Malformed RPC Packet Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Malformed RPC Packet Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch:
Microsoft Services for Unix 3.0
Solution:
Microsoft has released a patch:
Microsoft Services for Unix 3.0
-
Microsoft Q329209
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43447
References
Microsoft Malformed RPC Packet Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-057 (Microsoft)