(A Variant is Reported) Microsoft Windows TCP, IP, and ICMP Processing Errors Let Remote Users Deny Service and Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1014000
|
|
SecurityTracker URL: http://securitytracker.com/id?1014000
|
|
CVE Reference: CAN-2005-0356
(Links to External Site)
|
Date: May 18 2005
|
Impact: Denial of service via network, Execution of arbitrary code via network, Root access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Advisory
|
Version(s): 2000 SP4 and prior, XP SP2 and prior, 2003
|
Description: Several vulnerabilities were reported in the Microsoft Windows TCP/IP stack. A remote user can cause denial of service conditions or execute arbitrary code on the target system.
The system does not properly validate user-supplied IP packets. A remote user can send a specially crafted IP packet to the target
system to execute arbitrary code on the target system [CVE: CAN-2005-0048]. The code will run with System level privileges.
A
remote user can send a specially crafted ICMP pakcet to cause existing TCP connections to be reset [CVE: CAN-2004-0790].
A remote
user can send a specially crafted ICMP message to exploit a Path MTU discovery error and cause network performance on the target
system to degrade [CVE: CAN-2004-1060]. A remote user can send a specially crafted Path MTU value to trigger this flaw.
A remote
user can send a specially crafted spoofed TCP/IP message to cause the target system to stop responding to network connections [CVE:
CAN-2005-0688]. The flaw resides in the processing of TCP SYN packets when the source IP address and port is the same as the destination
IP address and port, causing a network loop.
The vendor credits Song Liu, Hongzhen Zhou, and Neel Mehta of ISS X-Force with reporting
IP validation vulnerability, Fernando Gont of Argentina's Universidad Tecnologica Nacional/Facultad Regional Haedo with reporting
the ICMP Connection Reset vulnerability and the ICMP Path MTU vulnerability, and Qualys with reporting the ICMP Path MTU vulnerability.
On
May 18, 2005, Microsoft reported a variant of the TCP vulnerability, affecting Windows 2000, Windows 2003, and Windows XP [CVE:
CAN-2005-0356]. A remote user can set arbitrary timer values for a TCP connection to cause existing TCP connections to be reset.
Systems that have applied Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, or the MS05-019 security update are not
affected. The new Microsoft Security Advisory is available at:
http://www.microsoft.com/technet/security/advisory/899480.mspx
|
Impact: A remote user can execute arbitrary code on the target system. The code will run with System level privileges.
A remote user
can cause TCP connections to be reset.
A remote user can cause network performance to degrade.
A remote user can cause the
target system to stop accepting network connections.
|
Solution: The vendor has issued the following fixes:
Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/detail
s.aspx?FamilyId=0C534EE0-DE5B-4002-BB69-C63ED03D5D9D
Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack
2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=B6D0437E-5A9E-4AA9-9E84-802A1BC5436C
Microsoft Windows XP 64-Bit
Edition Service Pack 1 (Itanium):
http://www.microsoft.com/downloads/details.aspx?FamilyId=A81DBEC3-58DC-4CE5-86E0-0F38931A8D4B
Microsoft
Windows XP 64-Bit Edition Version 2003 (Itanium):
http://www.microsoft.com/downloads/details.aspx?FamilyId=34DC5227-9B9B-4795-A1A0-5FA509B3AD52
Microsoft
Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=616B5880-4439-4D96-8355-D7FCFE40134B
Microsoft
Windows Server 2003 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=34DC5227-9B9B-4795-A1A0-5FA509B3AD52
A
restart is required.
|
Vendor URL: www.microsoft.com/technet/security/advisory/899480.mspx (Links to External Site)
|
Cause: Exception handling error, Input validation error, State error
|
Underlying OS: Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Wed, 18 May 2005 15:21:27 -0400
Subject: http://www.microsoft.com/technet/security/advisory/899480.mspx
|
> Microsoft Security Advisory (899480)
> Vulnerability in TCP Could Allow Connection Reset
> Published: May 18, 2005
>
> Microsoft is aware of a new vulnerability report affecting TCP/IP, a network
> component of Microsoft Windows. We are not aware of any attacks attempting to use
> the reported vulnerability and have no reports of customer impact at this time.
> Customers who have installed Windows XP Service Pack 2, Windows Server 2003 Service
> Pack 1, or the MS05-019 security update are not affected by this vulnerability.
|
|