Bug fixed in SP3

From: Grzegorz Tworek (grzesio@SECURITY.NET.PL)
Date: 08/01/02


Date:         Thu, 1 Aug 2002 10:00:52 +0200
From: Grzegorz Tworek <grzesio@SECURITY.NET.PL>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Some months ago I've informed MS about bug in WindowsNT and Windows2000.
They promised me to correct this bug in SP3 and they did it.

Bug is not very dangerous because needs admin rights.
Error in buffer size while sending socket causes BSOD immediately.

If you want to review CPP sources (1KB) or download compiled version (40KB)
you can visit http://gt-apps.w.interia.pl/bsod.htm

Note that NT 4.0 is still vulnerable. MS promised me appropriate patch but
they never sent it.

Regards,
Grzegorz Tworek
- - - - - - - - - - - - - - - - - - - - - -
Orion Instruments Polska
System Engineer, MCP, MCP+I, MCSE
http://www.orion.pl



Relevant Pages