Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
BID:8195
Info
Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
| Bugtraq ID: | 8195 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2003 12:00AM |
| Updated: | Jul 02 2003 12:00AM |
| Credit: | This vulnerability was announced by Microsoft. |
| Vulnerable: |
Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: |
Microsoft Windows 2000 Server SP4 |
Discussion
Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
The Microsoft SMTP service may cease responding or terminate when an e-mail message with a corrupt time stamp is received. It is not known if the service will restart automatically or requires manual intervention to resume normal operation.
This vulnerability was reported to affect Microsoft Windows 2000 Server with Service Pack 2 or 3 installed and Microsoft Exchange 2000 Server.
The Microsoft SMTP service may cease responding or terminate when an e-mail message with a corrupt time stamp is received. It is not known if the service will restart automatically or requires manual intervention to resume normal operation.
This vulnerability was reported to affect Microsoft Windows 2000 Server with Service Pack 2 or 3 installed and Microsoft Exchange 2000 Server.
Exploit / POC
Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
Solution:
This vulnerability was addressed in Windows 2000 Service Pack 4.
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP3
Solution:
This vulnerability was addressed in Windows 2000 Service Pack 4.
Microsoft Windows 2000 Server SP2
-
Microsoft Windows 2000 SP4
http://www.microsoft.com/windows2000/downloads/servicepacks/sp4/defaul t.asp
Microsoft Windows 2000 Server SP3
-
Microsoft Windows 2000 SP4
http://www.microsoft.com/windows2000/downloads/servicepacks/sp4/defaul t.asp
References
Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
References:
References: