Active Directory LDAP Processing Bug Lets Remote Users Deny Service
|
SecurityTracker Alert ID: 1019382 |
SecurityTracker URL: http://securitytracker.com/id/1019382
|
CVE Reference:
CVE-2008-0088
(Links to External Site)
|
Date: Feb 12 2008
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in Active Directory. A remote user can cause denial of service conditions.
A remote user can send specially crafted LDAP requests to cause the target system to become non-responsive and restart.
On Windows Server 2003 and Windows XP, authentication is required to exploit this vulnerability.
Thomas Garnier of SkyRecon reported this vulnerability.
|
Impact:
A remote user can cause the target system to become non-responsive and restart.
|
Solution:
The vendor has issued fixes for Active Directory and Active Directory Application Mode (ADAM).
A restart is required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-003.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-003.mspx (Links to External Site)
|
Cause:
Input validation error
|
Underlying OS: Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|