PT-2009-3703 · Microsoft · Server 2003+4
Justin Wyatt
·
Publicado
2009-06-10
·
Atualizado
2019-04-30
·
CVE-2009-1139
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Active Directory versions on Microsoft Windows 2000 SP4
Active Directory versions on Server 2003 SP2
Active Directory Application Mode (ADAM) versions on Windows XP SP2
Active Directory Application Mode (ADAM) versions on Windows XP SP3
Active Directory Application Mode (ADAM) versions on Server 2003 SP2
Description
A memory leak issue in the LDAP service allows remote attackers to cause a denial of service, resulting in memory consumption and service outage. This can be achieved via LDAP or LDAPS requests with unspecified OID filters.
Recommendations
For Active Directory on Microsoft Windows 2000 SP4, update to a newer version to mitigate the risk.
For Active Directory on Server 2003 SP2, update to a newer version to mitigate the risk.
For Active Directory Application Mode (ADAM) on Windows XP SP2, update to a newer version to mitigate the risk.
For Active Directory Application Mode (ADAM) on Windows XP SP3, update to a newer version to mitigate the risk.
For Active Directory Application Mode (ADAM) on Server 2003 SP2, update to a newer version to mitigate the risk.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adam
Active Directory
Server 2003
Windows 2000
Windows Xp