Microsoft Windows NT 4.0 Server file management function denial of service
| winnt-file-management-dos (12701) |
Description:
Microsoft Windows is vulnerable to a denial of service, caused by a vulnerability in the file management function. A remote or local attacker could send a specially-crafted request to a vulnerable program to cause a heap corruption and the program to crash.
Note: In order for this vulnerability to be exploited remotely, applications that are available remotely and make use of the affected function, must be installed on the system.
Consequences:
Denial of Service
Remedy:
Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS03-029. See References.
References:
- @stake, Inc. Security Advisory A072303-1: Windows NT 4.0 with IBM JVM Denial of Service.
- Microsoft Security Bulletin MS03-029: Flaw in Windows Function Could Allow Denial of Service (823803) .
- BID-8259: Microsoft Windows NT File Management Function Denial Of Service Vulnerability
- CVE-2003-0525: The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.
Platforms Affected:
- Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0 Server
- Microsoft Windows NT 4.0 Terminal Server
Reported:
Jul 23, 2003
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
