The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Flaw in Services for Unix 3.0 Interix SDK Could Allow Code Execution (Q329209)
Time: 02:03 EST/07:03 GMT | News Source: Microsoft | Posted By: Byron Hinson

All three vulnerabilities discussed in this bulletin involve the inclusion of the Sun RPC library in Microsoft’s Services for UNIX (SFU) 3.0 on the Interix SDK. Developers who created applications or utilities using the Sun RPC library from the Interix SDK need to evaluate three vulnerabilities.

Windows Services for UNIX (SFU) 3.0 provides a full range of cross-platform services to integrate Windows into existing UNIX environments. In version 3.0, the Interix subsystem technology is built in so that Windows Services for UNIX 3.0 can provide platform interoperability and application migration in one fully integrated and supported product from Microsoft. Developers who have integrated Windows into their existing UNIX environments may have used the Interix SDK to develop custom applications and utilities so that applications that only ran on the UNIX platform can now run in a Windows environment. Developers who used the Interix SDK to develop applications or utilities should read this bulletin.

The first vulnerability is an integer overflow in the XDR library that ships with the Sun RPC library on the Interix SDK for Microsoft’s Services for Unix (SFU) 3.0. An attacker could send a malicious RPC request to the RPC server from a remote machine and cause corruption in the server program. This can cause the server to fail and potentially allow the attacker to run code of his or her choice in the context of the server program.

The second vulnerability is a buffer overrun. An attacker could send a malicious RPC request to the RPC server with an improper parameter size check. This could lead to a buffer overrun, causing the server to fail and preventing it from servicing any further requests from clients.

The third vulnerability is an RPC implementation error. An application using the Sun RPC library does not properly check the size of client TCP requests. This could result in a denial of service to a server application using the Sun RPC library. The RPC library expects client TCP requests to specify the size of the record that follows. Because there is a flaw in the way RPC detects client packets, an attacker could send a malformed RPC request to the RPC server from a remote machine and cause the server to fail by not servicing any further client requests.

Patch availability

Download locations for this patch This patch can be installed on any of the following platforms:

http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43447

Write Comment
Return to News

  Displaying 426 through 433 of 433
Prev | First
  The time now is 4:27:51 PM ET.
Any comment problems? E-mail us
#426 By 4240821 (193.160.216.96) at 2/9/2025 10:37:58 PM
https://hotpic.cc/album/LmRVyTWhM87Pw
https://hotpic.cc/album/b3n2jXrVbpKKX
https://hotpic.cc/album/XL6oyCvKCMplE
https://hotpic.cc/album/kuqO0yalyDnWC
https://hotpic.cc/album/LpKE7VJFSvp4C
https://hotpic.cc/album/E471yDVbMAmky
https://hotpic.cc/album/4GKlUwv6RjnwR
https://hotpic.cc/album/0GbgTb9v7Gb7u
https://hotpic.cc/album/BMwTbd7igNNgD
https://hotpic.cc/album/KsRNpoWuAuRdn

#427 By 4240821 (142.111.253.203) at 2/10/2025 4:10:55 PM
https://hotpic.cc/album/yZiP3qLWhS1b8
https://hotpic.cc/album/VbPRYYnCYCKdN
https://hotpic.cc/album/pUOUBMcfHSyyu
https://hotpic.cc/album/8vMmjrVk0B7fV
https://hotpic.cc/album/omQC1AT6q6KUm
https://hotpic.cc/album/F49802hDFGS20
https://hotpic.cc/album/jmIpfNV29eHMc
https://hotpic.cc/album/CpTOdd4l22ep0
https://hotpic.cc/album/ii76CjX3evzrx
https://hotpic.cc/album/NW0GAHlD74Yqb

#428 By 4240821 (193.36.231.79) at 2/11/2025 7:37:28 AM
https://hotpic.cc/album/CyP8Xb4mvaNz7
https://hotpic.cc/album/BRqKVO5pP5CYo
https://hotpic.cc/album/bC4DQdJn3iSZF
https://hotpic.cc/album/evKN1Gj50dkBI
https://hotpic.cc/album/VkQ0RhHs9KozS
https://hotpic.cc/album/YgT3VWEh5w5nS
https://hotpic.cc/album/4QWPVSMLTbsN2
https://hotpic.cc/album/lInILWgzAv7kD
https://hotpic.cc/album/axaIwjysoXgJ5
https://hotpic.cc/album/d7jQYc1uG1duT

#429 By 4240821 (142.252.107.167) at 2/11/2025 7:12:35 PM
https://hotpic.cc/album/aT6qPP9DTAsz0
https://hotpic.cc/album/drvgAUvihTOxS
https://hotpic.cc/album/rXrlzkgYW56bc
https://hotpic.cc/album/Io5W605ywCBh1
https://hotpic.cc/album/46Oroo3JbJXlT
https://hotpic.cc/album/N3KQHZimXI9Jq
https://hotpic.cc/album/XL6oyCvKCMplE
https://hotpic.cc/album/OkhZW9olzZHTD
https://hotpic.cc/album/7WgBUfab2wxKm
https://hotpic.cc/album/3qHafQV004Xly

#430 By 4240821 (212.193.140.244) at 2/12/2025 9:14:14 AM
https://hotpic.cc/album/7qVxqqd08cNEy
https://hotpic.cc/album/7JdRXYiEnmKZe
https://hotpic.cc/album/SO6CCQJ698gre
https://hotpic.cc/album/BACucorUuWZqF
https://hotpic.cc/album/x0pa8br2BWLuS
https://hotpic.cc/album/MViVzzTmstYY1
https://hotpic.cc/album/G2LKepsDF3IPF
https://hotpic.cc/album/e6kv5cxw7I7Ft
https://hotpic.cc/album/rsgUolauuXNvU
https://hotpic.cc/album/ZJ2WiIujmCaOD

#431 By 4240821 (166.1.149.27) at 2/13/2025 1:44:35 AM
https://hotpic.cc/album/8u4Yg1wZ2FquB
https://hotpic.cc/album/o5snCqu4UvqON
https://hotpic.cc/album/baBC4tVuvJpp9
https://hotpic.cc/album/tTao5TxBNm5NN
https://hotpic.cc/album/4jeGSzvdY86Ko
https://hotpic.cc/album/hE262ZDWKN4Ua
https://hotpic.cc/album/ygmnyaz2mDRHN
https://hotpic.cc/album/yr8oNQu4y7WVd
https://hotpic.cc/album/RLhm3JpTCNezj
https://hotpic.cc/album/vMz7eXByf00FO

#432 By 4240821 (193.228.48.158) at 2/13/2025 8:16:31 AM
https://hotpic.cc/album/YBRVWw6L5gR6t
https://hotpic.cc/album/yrn3wNzQfdmVp
https://hotpic.cc/album/b0iW3eP5PxkPq
https://hotpic.cc/album/TQ8MQ7voR7XBO
https://hotpic.cc/album/BqdqTSlr67h3W
https://hotpic.cc/album/3FSfblI6zKyQP
https://hotpic.cc/album/efJ3qPHk9PSJL
https://hotpic.cc/album/FDGr7tkD3tbmj
https://hotpic.cc/album/TJJlcpiLSlHtu
https://hotpic.cc/album/LpKE7VJFSvp4C

#433 By 4240821 (142.111.253.203) at 2/13/2025 9:27:23 PM
https://hotpic.cc/album/0cLmibxSIFx0S
https://hotpic.cc/album/KsRNpoWuAuRdn
https://hotpic.cc/album/TzVlplmOECsuQ
https://hotpic.cc/album/qBh1eyKKCuyl3
https://hotpic.cc/album/4jeGSzvdY86Ko
https://hotpic.cc/album/ossxtiO9uNpaR
https://hotpic.cc/album/6y8Syd7pxrQMr
https://hotpic.cc/album/DgppcuxTXPG0W
https://hotpic.cc/album/uPpXszqb7I9RD
https://hotpic.cc/album/gJuwmEaOpTDIs

Write Comment
Return to News
  Displaying 426 through 433 of 433
Prev | First
  The time now is 4:27:51 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *