PT-2002-3040 · Openldap+2 · Ldap+4

Publicado

2002-12-31

·

Atualizado

2019-04-30

·

CVE-2002-2328

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Windows 2000
Description The issue concerns Active Directory in Windows 2000, specifically when it supports Kerberos V authentication and GSSAPI. A remote attacker can cause a denial of service, leading to a system hang, by using an LDAP client to set the page length to zero during a large request.
Recommendations For Windows 2000, consider restricting access to the LDAP service to minimize the risk of exploitation until a fix is available. Avoid using the LDAP client to set the page length to zero during large requests.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-2328

Produtos afetados

Active Directory
Gssapi
Kerberos
Ldap
Windows 2000