| Definition Id: oval:org.mitre.oval:def:268 |
Version: 10
Last Modified: 2011-09-14
|
| Title: |
Windows XP Messenger Service Buffer Overflow |
| Description: |
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack. |
| Family: |
windows |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2003-0717
|
| Platform(s): |
Microsoft Windows XP |
Product(s): |
|
| Definition Synopsis: |
- Software section
- a vulnerable version of wkssvc.dll exists
- no service pack is installed and wkssvc.dll is less than 5.1.2600.120
- OR service pack 1 is installed and wkssvc.dll is less than 5.1.2600.1301
- AND a vulnerable version of msgsvc.dll exists
- no service pack is installed and msgsvc.dll is less than 5.1.2600.120
- OR service pack 1 is installed and msgsvc.dll is less than 5.1.2600.1301
- AND NOT the patch q828035 is installed (Hotfix key)
- AND Windows XP (sp1 or earlier) is installed
- AND Configuration section
|