• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » July 2002 » Unchecked Buffer In Remote Access Service Patch Update!

Unchecked Buffer In Remote Access Service Patch Update!

Posted by: [PM] on: 07/03/2002 07:16 PM [ Print | 0 comment(s) ] · 1321 views

Title: Unchecked Buffer in Remote Access Service Phonebook Could Lead to Code Execution (Q318138)
Released: 12 June 2002
Revised: 02 July 2002 (Version 2.0) Software: Windows NT 4.0, NT 4.0 Terminal Server Edition, 2000, XP, Routing and Remote Access Server (RRAS)
Impact: Local Privilege Escalation
Max Risk: Critical Read more...



On June 12, 2002, Microsoft released the original version of this bulletin. On July 2, 2002, the bulletin was updated to reflect the availability of a revised patch. Although the original patch completely eliminated the vulnerability, it had the side effect of preventing non-administrative users from making VPN connections in some cases. The revised patch correctly handles VPN connections. The revised patch is immediately available from the Download Center and will be soon made available via WindowsUpdate. The Remote Access Service (RAS) provides dial-up connections between computers and networks over phone lines. RAS is delivered as a native system service in Windows NT 4.0, Windows 2000 and Windows XP, and also is included in a separately downloadable Routing and Remote Access Server (RRAS) for Windows NT 4.0. All of these implementations include a RAS phonebook, which is used to store information about telephone numbers, security, and network settings used to dial-up remote systems. A flaw exists in the RAS phonebook implementation: a phonebook value is not properly checked, and is susceptible to a buffer overrun. The overrun could be exploited for either of two purposes: causing a system failure, or running code on the system with LocalSystem privileges. If an attacker were able to log onto an affected server and modify a phonebook entry using specially malformed data, then made a connection using the modified phonebook entry, the specially malformed data could be run as code by the system. Download locations for this patch Microsoft Windows NT 4.0:
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/default.asp Microsoft Windows NT 4.0 running RRAS (English Only):
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/default.asp Microsoft Windows NT 4.0 Terminal Server Edition:
http://www.microsoft.com/ntserver/terminalserver/downloads/security/q318138/default.asp Microsoft Windows NT 4.0 Terminal Server Edition running RRAS (English Only):
http://www.microsoft.com/ntserver/terminalserver/downloads/security/q318138/default.asp Microsoft Windows 2000:
http://www.microsoft.com/windows2000/downloads/security/q318138/default.asp Microsoft Windows XP:
http://www.microsoft.com/downloads/release.asp?ReleaseID=38833 Microsoft Windows XP 64-bit Edition:
http://www.microsoft.com/downloads/release.asp?ReleaseID=39011


Digg it! Del.icio.us Technorati Furl Google Bookmarks

« Nero Burning Rom 5.5.9.0 Released! · Unchecked Buffer In Remote Access Service Patch Update! · EPoX BIOS Updates! »

Warp2Search.net » News » July 2002 » Unchecked Buffer In Remote Access Service Patch Update!

Latest News

· Windows Home Server Power Pack 3: November 24
· MemSet 4.1
· SetFSB 2.2.134.98
· ProduKey 1.40
· Hiren's BootCD 10.1
· FinalBurner Free 2.15.0.171
· Replay Music 3.92
· Google Chrome BETA 4.0.249.4
· Sapphire 5970 Cfx and HIS 5970 CFx Review
· Ultra X4 500 W Power Supply Review
· PC Tools ThreatFire 4.7.0.9
· ZipGenius 6.2.0.2000
· Avira AntiVir Personal - FREE Antivirus 9.0.0.415
· Wise Disk Cleaner 4.83
· Realtek High Definition Audio for Vista\Win 7 2.37
· Realtek High Definition Audio for 2K\XP\03 2.37
· Thermaltake SD100 mini ITX Home Theater Chassis Review
· Foobar 1.0 Beta 1

Community Forum

· re:How to save mobile text message to pc?
Posted by lance58

· How to save mobile text message to pc?
Posted by janneluu

· S.T.A.L.K.E.R.: Call of Pripyat Benchmark
Posted by Regeneration

· Thermaltake BlacX Duet Dual Hard Drive Docking Station Review @ Tweaknews
Posted by Tweaknews

· Noctua NH-D14 Premium CPU Cooler Review @ Clunk.org.uk
Posted by Clunk


Nodes To Friends





Online Users

There are currently 498 user(s) online:
Ask Jeeves, Cuil, Google, Live Search, MSN, Yahoo

© 2007-2009 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002 - 2009 Esselbach Internet Solutions