Microsoft Windows Negotiate SSP 代码问题漏洞

漏洞信息详情

Microsoft Windows Negotiate SSP 代码问题漏洞

漏洞简介

Windows 2000, Windows XP, and Windows Server 2003的Negotiate Security Software Provider (SSP)界面存在代码问题漏洞。远程攻击者借助精心制作的在认证协议区期间的SPNEGO NegTokenInit请求导致服务拒绝(无效的参考解崩溃)或者执行任意代码。

漏洞公告

Avaya has released an advisory to announce that Avaya System Products shipping on Microsoft platforms are also affected by this vulnerability. Avaya advise that customers follow the Microsoft recommendations for the resolution of this issue. The aforementioned advisory can be viewed at the following location:

http://support.avaya.com/japple/css/japple?temp.groupID=&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=161384&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()

Microsoft has released fixes.

US-CERT has released an advisory TA04-104A to address this and other issues. Please see the referenced advisory for more information.

Microsoft Windows 2000 Server SP2

Microsoft Windows 2000 Advanced Server SP2

Microsoft Windows XP 64-bit Edition SP1

Microsoft Windows 2000 Advanced Server SP4

Microsoft Windows 2000 Professional SP3

Microsoft Windows Server 2003 Enterprise Edition

Microsoft Windows 2000 Professional SP2

Microsoft Windows Server 2003 Web Edition

Microsoft Windows XP Home

Microsoft Windows 2000 Advanced Server SP3

Microsoft Windows XP Home SP1

Microsoft Windows XP 64-bit Edition Version 2003 SP1

Microsoft Windows Server 2003 Enterprise Edition Itanium 0

Microsoft Windows 2000 Server SP3

Microsoft Windows Server 2003 Standard Edition

Microsoft Windows XP 64-bit Edition Version 2003

Microsoft Windows 2000 Server SP4

Microsoft Windows XP Professional

Microsoft Windows 2000 Professional SP4

参考网址

来源:BID

链接:https://www.securityfocus.com/bid/10113

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1962

来源:CERT-VN

链接:http://www.kb.cert.org/vuls/id/638548

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1997

来源:CERT

链接:http://www.us-cert.gov/cas/techalerts/TA04-104A.html

来源:VULNWATCH

链接:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html

来源:CIAC

链接:http://www.ciac.org/ciac/bulletins/o-114.shtml

来源:XF

链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/15715

来源:MS

链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1808

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享