Microsoft Windows DNS Server未初始化内存远程拒绝服务漏洞

漏洞起因
设计错误
危险等级

 
影响系统
Microsoft Windows Server 2008 Standard Edition SP2
 Microsoft Windows Server 2008 Standard Edition Release Candidate
 Microsoft Windows Server 2008 Standard Edition R2 SP1
 Microsoft Windows Server 2008 Standard Edition R2
 Microsoft Windows Server 2008 Standard Edition Itanium
 Microsoft Windows Server 2008 Standard Edition 0
 Microsoft Windows Server 2008 Standard Edition – Sp2 Web
 Microsoft Windows Server 2008 Standard Edition – Sp2 Storage
 Microsoft Windows Server 2008 Standard Edition – Sp2 Hpc
 Microsoft Windows Server 2008 Standard Edition – Gold Web
 Microsoft Windows Server 2008 Standard Edition – Gold Storage
 Microsoft Windows Server 2008 Standard Edition – Gold Standard
 Microsoft Windows Server 2008 Standard Edition – Gold Itanium
 Microsoft Windows Server 2008 Standard Edition – Gold Hpc
 Microsoft Windows Server 2008 Standard Edition – Gold Enterprise
 Microsoft Windows Server 2008 Standard Edition – Gold Datacenter
 Microsoft Windows Server 2008 Standard Edition – Gold
 Microsoft Windows Server 2008 R2 x64 SP1
 Microsoft Windows Server 2008 R2 x64 0
 Microsoft Windows Server 2008 R2 Standard Edition 0
 Microsoft Windows Server 2008 R2 Itanium SP1
 Microsoft Windows Server 2008 R2 Itanium 0
 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 0
 Microsoft Windows Server 2008 R2 Enterprise Edition 0
 Microsoft Windows Server 2008 R2 Datacenter SP1
 Microsoft Windows Server 2008 R2 Datacenter 0
 Microsoft Windows Server 2008 for x64-based Systems SP2
 Microsoft Windows Server 2008 for x64-based Systems R2
 Microsoft Windows Server 2008 for x64-based Systems 0
 Microsoft Windows Server 2008 for Itanium-based Systems SP2
 Microsoft Windows Server 2008 for Itanium-based Systems R2
 Microsoft Windows Server 2008 for Itanium-based Systems 0
 Microsoft Windows Server 2008 for 32-bit Systems SP2
 Microsoft Windows Server 2008 for 32-bit Systems 0
 Microsoft Windows Server 2008 Enterprise Edition SP2
 Microsoft Windows Server 2008 Enterprise Edition Release Candidate
 Microsoft Windows Server 2008 Enterprise Edition 0
 Microsoft Windows Server 2008 Datacenter Edition SP2
 Microsoft Windows Server 2008 Datacenter Edition Release Candidate
 Microsoft Windows Server 2008 Datacenter Edition 0
 Microsoft Windows Server 2008 SP2 Beta
 Microsoft Windows Server 2008 – Sp2 Enterprise X64
 Microsoft Windows Server 2003 x64 SP2
 Microsoft Windows Server 2003 x64 SP1
 Microsoft Windows Server 2003 Web Edition SP2
 Microsoft Windows Server 2003 Web Edition SP1
 Microsoft Windows Server 2003 Web Edition
 Microsoft Windows Server 2003 Terminal Services 0
 Microsoft Windows Server 2003 Standard x64 Edition
 Microsoft Windows Server 2003 Standard Edition SP2
 Microsoft Windows Server 2003 Standard Edition SP1
 Microsoft Windows Server 2003 Standard Edition
 Microsoft Windows Server 2003 Itanium SP2
 Microsoft Windows Server 2003 Itanium SP1
 Microsoft Windows Server 2003 Itanium 0
 Microsoft Windows Server 2003 Enterprise x64 Edition SP2
 Microsoft Windows Server 2003 Enterprise x64 Edition
 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
 Microsoft Windows Server 2003 Enterprise Edition SP1
 Microsoft Windows Server 2003 Enterprise Edition
 Microsoft Windows Server 2003 Datacenter x64 Edition SP2
 Microsoft Windows Server 2003 Datacenter x64 Edition
 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
 Microsoft Windows Server 2003 Datacenter Edition SP1
 Microsoft Windows Server 2003 Datacenter Edition
 
不受影响系统
 
危害
远程攻击者可以利用漏洞使服务停止响应。
 
攻击所需条件
攻击者必须访问Microsoft Windows DNS服务器。
 
漏洞信息
Microsoft Windows是一款流行的操作系统。
Windows DNS服务处理一个查询不存在域的请求时存在错误,不正确处理未初始化的内存对象可导致DNS服务停止响应,造成拒绝服务攻击。
 
测试方法
 
厂商解决方案
用户可参考如下供应商提供的安全公告获得补丁信息:
http://www.microsoft.com/technet/security/Bulletin/MS11-058.mspx
 
漏洞提供者
Microsoft

发表评论?

0 条评论。

发表评论