also @ TechSpot: Apple previews OS X 10.8 Mountain Lion, brings iOS and the Mac closer together
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Begin your free trial now Pay-as-you-go options starting at $10/user/month

Buffer Overrun in Windows Could Lead to Data Corruption

Thread Tools Search this Thread
  #1  
Old 07-12-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Buffer Overrun in Windows Could Lead to Data Corruption

Affected Software:
Microsoft Windows NT Server 4.0
Microsoft Windows NT Server 4.0, Terminal Server Edition
Microsoft Windows 2000
Windows XP Professional

A flaw exists in the way that the server validates the parameters of an SMB packet. When a client system sends an SMB packet to the server system, it includes specific parameters that provide the server with a set of “instructions.” In this case, the server is not properly validating the buffer length established by the packet. If the client specifies a buffer length that is less than what is needed, it can cause the buffer to be overrun.

By sending a specially crafted SMB packet request, an attacker could cause a buffer overrun to occur. If exploited, this could lead to data corruption, system failure, or—in the worst case—it could allow an attacker to run the code of their choice. An attacker would need a valid user account & would need to be authenticated by the server to exploit this flaw.

Patch availability
Download locations for this patch.
  #2  
Old 07-12-2003
tkteo's Avatar
TechSpot Member
 
Location: where Dan Fogelberg went to college
Member since: Mar 2003, 61 posts
The patch executable will not install if Win2K SP4 is installed. The error message says that certain files in the executable are older than SP4, and SP3 or earlier is required for the patch to install.

Last edited by tkteo; 07-12-2003 at 01:20 PM..
  #3  
Old 07-12-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Just checked into that on the proper knowledge base article for this patch. Yep, Windows 2000 SP4 supersedes this patch alright.
Closed Thread

Similar Topics
Topic Replies Forum
Visual C++ Buffer Overrun please help 6 Virus and Malware Removal
Buffer Overrun.....& hijackers 10 Virus and Malware Removal
Buffer Overrun in Windows Help & Support Center 0 General Discussion
Buffer Overrun in Windows Kernel Message Handling 1 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 01:35 PM.