Windows 2000 DCOM客户端内存泄露漏洞

漏洞信息详情

Windows 2000 DCOM客户端内存泄露漏洞

漏洞简介

Windows 2000 SP3之前版本的DCOM客户端不能正确地在发送\”alter context\”请求之前清除内存,远程攻击者可能通过发觉会话获得敏感信息。

漏洞公告

It has been reported that this issue is fixed in Windows 2000 SRP1:
Microsoft Windows 2000 Professional

Microsoft Windows 2000 Server SP2

Microsoft Windows 2000 Advanced Server SP1

Microsoft Windows 2000 Server SP1

Microsoft Windows 2000 Advanced Server SP2

Microsoft Windows 2000 Professional SP2

Microsoft Windows 2000 Advanced Server

Microsoft Windows 2000 Professional SP1

Microsoft Windows 2000 Server

参考网址

来源: BID
名称: 4410
链接:http://www.securityfocus.com/bid/4410

来源: XF
名称: win2k-dcom-memory-leak(8739)
链接:http://www.iss.net/security_center/static/8739.php

来源: BINDVIEW
名称: 20020402 Windows 2000 DCOM clients may leak sensitive information onto the network
链接:http://www.bindview.com/Services/razor/Advisories/2002/adv_dcom.cfm

来源: MSKB
名称: Q300367
链接:http://support.microsoft.com/default.aspx?scid=kb;EN-US;q300367

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享