漏洞信息详情
Microsoft Windows 2000 TroubleShooter ActiveX 控制缓冲区溢出漏洞
- CNNVD编号:CNNVD-200311-038
- 危害等级: 超危
- CVE编号:
CVE-2003-0662
- 漏洞类型:
缓冲区错误
- 发布时间:
2003-11-17
- 威胁类型:
远程
- 更新时间:
2019-05-05
- 厂 商:
microsoft - 漏洞来源:
Discovery credited… -
漏洞简介
Microsoft Windows 2000 SP4及其早期版本中的Troubleshooter ActiveX Control (Tshoot.ocx)存在缓冲区溢出漏洞。远程攻击者可以通过具有RunQuery2类函数中超长参数的HTML文档执行任意代码。
漏洞公告
Microsoft has released security bulletin MS03-042 with patches to address this issue. It should be noted that affected Windows 2000 systems require a minimum of Service Pack 2 to apply available patches.
Microsoft has released updated version 1.1 of Microsoft security bulletin MS03-042 containing updated product specific information for the security patch. Revision 2.0 of the bulletin was also released to provide updated patches to address an unrelated problem with Debug Programs (SeDebugPrivilege). These patches can be found in the same location as the initial patches. Please see the updated bulletin for further details.
Microsoft Windows 2000 Server SP2
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17
Microsoft Windows 2000 Datacenter Server SP3
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Server SP3
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17
Microsoft Windows 2000 Server SP4
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Professional SP3
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Professional SP2
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17
Microsoft Windows 2000 Professional SP4
-
Microsoft KB826232
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en“>
http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4
Microsoft Windows 2000 Datacenter Server SP4
参考网址
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-042
来源:VULNWATCH
链接:http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0015.html
来源:CERT-VN
链接:http://www.kb.cert.org/vuls/id/989932
来源:BID
链接:http://www.securityfocus.com/bid/8833
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A237
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/13423
来源:FULLDISC
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012205.html
来源:NTBUGTRAQ
链接:http://marc.info/?l=ntbugtraq&m=106632192709608&w=2
来源:CERT