Thread-topic: [SA20000] Microsoft Windows MSDTC Denial of Service
>
> TITLE:
> Microsoft Windows MSDTC Denial of Service
>
> SECUNIA ADVISORY ID:
> SA20000
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Less critical
>
> IMPACT:
> DoS
>
> WHERE:
> From local network
>
> OPERATING SYSTEM:
> Microsoft Windows 2000 Advanced Server
>
> Microsoft Windows 2000 Datacenter Server
>
> Microsoft Windows 2000 Professional
>
> Microsoft Windows 2000 Server
>
> Microsoft Windows Server 2003 Datacenter Edition
>
> Microsoft Windows Server 2003 Enterprise Edition
>
> Microsoft Windows Server 2003 Standard Edition
>
> Microsoft Windows Server 2003 Web Edition
>
> Microsoft Windows XP Home Edition
>
> Microsoft Windows XP Professional
>
>
> DESCRIPTION:
> Two vulnerabilities have been reported in Microsoft Windows, which
> can be exploited by malicious people to cause a DoS (Denial of
> Service).
>
> 1) A boundary error in the MSDTC (Microsoft Distributed Transaction
> Coordinator) can be exploited to cause the component and dependent
> services to stop responding by sending a specially crafted network
> message.
>
> 2) Another boundary error in the MSDTC (Microsoft Distributed
> Transaction Coordinator) can be exploited to cause the component and
> dependent services to stop responding by sending a specially crafted
> network message.
>
> SOLUTION:
> Apply patches.
>
> Microsoft Windows 2000 SP4:
>
380-0E5C-4B80-9710-95E1B35AFD83
>
> Microsoft Windows XP SP1 / SP2:
>
3B2-727B-46B6-82D1-F2CBD916FE32
>
> Microsoft Windows Server 2003:
>
5C7-8924-46DA-8573-457957EEA0D7
>
> Microsoft Windows Server 2003 for Itanium-based systems:
>
335-79EA-46CE-8D3C-0AA91EEFFF02
>
> PROVIDED AND/OR DISCOVERED BY:
> 1) The vendor credits eEye Digital Security and Xiao Chen, McAfee.
> 2) The vendor credits eEye Digital Security and Kai Zhang, VenusTech.
>
> ORIGINAL ADVISORY:
> MS06-018 (KB913580):
>
>
>