Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-0567
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0567

Description:
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/18259

ST
  1012517

SAID
  Secunia Advisory: SA13466

OSVDB
  12370

MS
  http://www.microsoft.com/technet/security/bulletin/MS04-045.mspx

CIAC
  http://www.ciac.org/ciac/bulletins/p-054.shtml

CERT-VN
  378160

BID
  11922


Return to the previous page.