Denial of Service Condition in Microsoft NNTP Service for Windows 2000/NT

A memory leak condition exists in the way certain Windows OSs (see above) process new postings when using the Network News Transfer Protocol (NNTP) service.

Ken Pfeil

August 14, 2001

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported August 14, 2001, byMicrosoft.

VERSIONS AFFECTED

  • Microsoft Windows 2000 Server

  • Microsoft Windows 2000 Advanced Server

  • Microsoft Windows 2000 Datacenter Server

  • Microsoft Windows NT Server 4.0

  • Microsoft Windows NT Server, Enterprise Edition

 

DESCRIPTION
Amemory leak condition exists in the way certain Windows OSs (see above) processnew postings when using the Network News Transfer Protocol (NNTP) service. If anattacker sends a large number of posts of a particular construction, those postscan deplete the server’s available memory and disrupt service. A user canreboot the server to resume normal service. Only servers that accept newpostings are vulnerable to this condition.

 

VENDOR RESPONSE

Thevendor, Microsoft, has released securitybulletin MS01-043to address this vulnerability and recommends that users apply whichever of thefollowing patches is relevant to their system:

 

WindowsNT 4.0 Server and Enterprise Server

 

Windows2000 Server and Advanced Server

 

Windows 2000 Datacenter Server patches arehardware-specific and available only through the OEM.

 

CREDIT
Discovered by AidenORawe.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like