Microsoft SMTP Service Buffer Overflow in Processing DNS Responses May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1011636
|
|
SecurityTracker URL: http://securitytracker.com/id?1011636
|
|
CVE Reference: CAN-2004-0840
(Links to External Site)
|
Date: Oct 12 2004
|
Impact: Execution of arbitrary code via network, Root access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Description: A vulnerability was reported in the Microsoft SMTP service on Windows XP and 2003. A remote DNS server can execute arbitrary code on the target system.
Microsoft reported that the SMTP service does not properly process DNS lookup responses. A remote user with control over a DNS server
or with the ability to spoof a DNS server can have the DNS server provide a specially crafted lookup response to the target system
to execute arbitrary code on the target system. The code will run with System level privileges.
The Microsoft Exchange Server
2003 Routing Engine component is also affected (on Windows 2000 SP3 or SP4).
|
Impact: A remote DNS server (or a remote user with the ability to spoof a DNS server) can execute arbitrary code on the target system with System level privileges.
|
Solution: The vendor has issued a fix.
Microsoft Windows XP 64-Bit Edition Version 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b53e890d-7d6a-4bb4-8e28-15d66
1014288
Microsoft Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=d7767455-1ca0-49ea-8f71-76da5d451a07
Microsoft
Windows Server 2003 64-Bit Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b53e890d-7d6a-4bb4-8e28-15d661014288
Microsoft
Exchange Server 2003 when installed on Microsoft Windows 2000 Service Pack 3 or Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?
FamilyId=313BEC77-0845-46D4-BB43-06C792ADB2EA
A fix is also included in Microsoft Exchange Server 2003 and Microsoft Exchange
Server 2003 Service Pack 1 when installed on Microsoft Windows Server 2003 (uses the Windows 2003 SMTP component).
These patches
require a system restart.
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms04-035.mspx (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 12 Oct 2004 13:30:43 -0400
Subject: http://www.microsoft.com/technet/security/bulletin/ms04-035.mspx
|
MS04-035
http://www.microsoft.com/technet/security/bulletin/ms04-035.mspx
|
|