[NT] Windows .NET Server (RC1) and MSDE Security Vulnerability

From: support@securiteam.com
Date: 09/03/02


From: support@securiteam.com
To: list@securiteam.com
Date: Tue,  3 Sep 2002 19:39:28 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Windows .NET Server (RC1) and MSDE Security Vulnerability
------------------------------------------------------------------------

SUMMARY

Though Microsoft Windows .NET Server is still a release candidate,
presently at RC1, NGSSoftware has decided to release this warning as
anyone evaluating .NET Server is vulnerable if IIS 6 has been installed.
When IIS 6 is installed, the Microsoft Desktop Engine (MSDE) is also
installed. MSDE is based on SQL Server technology designed to support
transactional applications in the background. This version of MSDE is
vulnerable to the Name Resolution buffer overflows that allow an attacker
without a UserID and password to compromise the server. For more details
about these overflows please see
<http://www.nextgenss.com/advisories/mssql-udp.txt>
http://www.nextgenss.com/advisories/mssql-udp.txt, but to summarize an
attacker can send a single UDP packet to port 1434 on the machine running
MSDE and overflow a buffer gaining control of the process' path of
execution.

DETAILS

Fix Information:
Customers evaluating .NET Server should apply the following patch:
<http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS02-043.asp> http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS02-043.asp

Whilst
<http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS02-039.asp> http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS02-039.asp specifically addresses these overflows, the former URL includes a fix for this issue and others.

ADDITIONAL INFORMATION

The information has been provided by <mailto:nisr@nextgenss.com>
NGSSoftware Insight Security Research.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: ASPNET User Problem in Shared Hosting Environment
    ... I am going to go berserk if they put .NET Server out with the FrontPage 2002 ... Extensions and ASP.NET security flaws. ... it is the whole premise of the change of direction Microsoft ... I got into the shared hosting with Microsoft Technology business because my ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • DCOMCNFG properties in w2003 server
    ... I'm trying ti edit the security of SQL Distribution object ... in DCOMCNFG utility in .NET server. ...
    (microsoft.public.windows.server.general)
  • Windows .NET Server (RC1) and MSDE (#NISR03092002B)
    ... .NET Server is vulnerable if IIS 6 has been installed. ... installed the Microsoft Desktop Engine (MSDE) is also installed. ... Name Resolution buffer overflows that allows an attacker without a UserID ...
    (Bugtraq)
  • Re: [Full-Disclosure] Coming soon: CPU fix for buffer overflows
    ... leading to cruddier and more bloated code and yet more security ... > data to the buffer than it can hold, causing it to overflow into the next ... > processor chips that will deal with the problem. ... > buffer overflows when used with a new version of Windows XP. ...
    (Full-Disclosure)
  • MSDE SQL Server Does Not Exist or Access Denied
    ... "SQL Server Does Not Exist or Access ... Denied" when trying to connect to the MSDE Server. ... The security for the database has been opened up to everyone ... condition of the network connection. ...
    (microsoft.public.sqlserver.msde)