search PRIV & ALL sites linked here

Thursday, September 10, 2009

Array index error in the SMB2 protocol implementation in srv2.sys in Microsoft Windows 7, Server 2008, and Vista Gold, SP1, and SP2 allows remote attackers to cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location. NOTE: some of these details are obtained from third party information.
^ from CVE 2009-3103

Although in this CVE candidate it only warns of possible denial of service.. From other sources, primarily the MICROSOFT.COM webiste they warn of possible remote execution of code which could lead to a Conficker like worm that infected millions of computers last year, on to early 2009.

here is the Microsoft advisory which differs is wording from the CVE.

+++

on a lighter note we may have found some hosting overseas for our new dedicated host.
please make some comments if possible fellaz.

http://www.hetzner.de/en/hosting/produkte_rootserver_ds/ds3000/

http://www.isgenug.de/


http://www.hetzner.de/en/hosting/produktmatrix/rootserver-produktmatrix/

No comments:

Post a Comment