[NT] Microsoft Windows XP RPC Cache Memory Leak Vulnerabiliry

From: SecuriTeam (support_at_securiteam.com)
Date: 07/05/05

  • Next message: SecuriTeam: "[TOOL] DetectCon Detects Hidden Ports"
    To: list@securiteam.com
    Date: 5 Jul 2005 13:57:54 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Microsoft Windows XP RPC Cache Memory Leak Vulnerabiliry
    ------------------------------------------------------------------------

    SUMMARY

    When you run a program that uses the Windows Management Instrumentation
    (WMI) service in Microsoft Windows XP, the memory that is used by a remote
    procedure call (RPC) cache may not be freed, and a memory leak may occur.
    The RPC cache may grow so large that it causes the program and Windows XP
    to become unresponsive.

    DETAILS

    Vulnerable Systems:
     * Rpcrt4.dll library version 5.1.2600.2575 and prior

    This problem may occur if many expired and unused security contexts are
    generated every second. (Security contexts are generated by the program
    that you are running.) The RPC cache is cleaned up at a rate of nine
    security context entries every 10 seconds. If the security contexts are
    generated at a faster rate than the cache is cleaned up, the cache grows
    larger and eventually causes the problem.

    Vendor Status:
    A supported hotfix is now available from Microsoft, but it is only
    intended to correct the problem that is described in this article. Only
    apply it to systems that are experiencing this specific problem. This
    hotfix may receive additional testing. Therefore, if you are not severely
    affected by this problem, we recommend that you wait for the next Windows
    XP service pack that contains this hotfix.

    To resolve this problem immediately, contact Microsoft Product Support
    Services to obtain the hotfix. For a complete list of Microsoft Product
    Support Services phone numbers and information about support costs, visit
    the following Microsoft Web site:
     <http://support.microsoft.com/default.aspx?scid=fh;[LN];CNTACTMS>
    http://support.microsoft.com/default.aspx?scid=fh;[LN];CNTACTMS

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:juha-matti.laurio@netti.fi>
    Juha-Matti Laurio .
    The original article can be found at:
    <http://support.microsoft.com/kb/890196/EN-US/>
    http://support.microsoft.com/kb/890196/EN-US/

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[TOOL] DetectCon Detects Hidden Ports"

    Relevant Pages

    • lame server messages in named.log
      ... Mar 30 05:42:30.526 security: info: client 202.52.250.176#1052: ... query (cache) denied ...
      (RedHat)
    • lame server messages in named.log
      ... Mar 30 05:42:30.526 security: info: client 202.52.250.176#1052: ... query (cache) denied ...
      (RedHat)
    • [PATCH 16/19] CacheFiles: Deal with LSM when accessing the cache
      ... Make the Cachefiles module deal with LSM/SELinux security when accessing the ... SECURITY MODEL AND SELINUX ... security context that is not appropriate for accessing the cache - either ... struct kstatfs stats; ...
      (Linux-Kernel)
    • Re: MBSA problem
      ... the MS Baseline Security Analizer has given me (I ... > Windows Scan Results ... > Hotfix Description ... > Check passed Macro Security 4 Microsoft Office productare installed. ...
      (microsoft.public.windowsxp.security_admin)
    • [PATCH 00/45] Permit filesystem local caching [ver #35]
      ... These patches add local caching for network filesystems such as NFS. ... FS-Cache asks the cache backend, in this case CacheFiles to honour the ... FS-Cache attempts to provide a caching facility to a network filesystem such ... A patch to allow the security label of a key to be retrieved. ...
      (Linux-Kernel)