Microsoft Host Integration Server Bugs Let Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1026168 |
|
SecurityTracker URL: http://securitytracker.com/id/1026168
|
|
CVE Reference:
CVE-2011-2007, CVE-2011-2008
(Links to External Site)
|
Date: Oct 11 2011
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2004 SP1, 2006 SP1, 2009, 2010
|
Description:
Two vulnerabilities were reported in Microsoft Host Integration Server. A remote user can cause denial of service conditions.
A remote user can send specially crafted data to the target system on UDP port 1478 or TCP ports 1477 and 1478 to trigger a flaw in snabase.exe, snaserver.exe, snalink.exe, or mngagent.exe.
A remote user can cause the system to enter an infinite loop and stop responding to new requests [CVE-2011-2007].
A remote user can cause the system to access unallocated memory and stop responding to new requests [CVE-2011-2008].
Microsoft Host Integration Server 2000 SP2 is not affected.
|
Impact:
A remote user can cause the SNA server service to stop responding to new requests.
|
Solution:
The vendor has issued the following fixes:
Microsoft Host Integration Server 2004 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=b7536139-63ea-482a-8d1c-0faad1fcfaa4
Microsoft Host Integration Server 2006 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=3bc0c89c-56b2-4463-b671-2a58bed9667b
Microsoft Host Integration Server 2009:
http://www.microsoft.com/downloads/details.aspx?familyid=28716ed4-f215-4c69-b6b8-63fbeecefc5b
Microsoft Host Integration Server 2010:
http://www.microsoft.com/downloads/details.aspx?familyid=dbbd67d8-68aa-424d-8eaf-a273a71624d1
The Microsoft advisory is available at:
http://technet.microsoft.com/en-us/security/bulletin/ms11-082
|
Vendor URL: technet.microsoft.com/en-us/security/bulletin/ms11-082 (Links to External Site)
|
Cause:
Access control error, State error
|
Underlying OS:
Windows (2003), Windows (2008)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|