安全研究

安全漏洞
Windows 分段IP包重组拒绝服务攻击漏洞

发布日期:2000-05-21
更新日期:2000-05-22

受影响系统:
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0 Workstation
- Microsoft Windows NT 4.0 Server
- Microsoft Windows NT 4.0 Server, Enterprise Edition
- Microsoft Windows NT 4.0 Server, Terminal Server Edition
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
描述:
当以每秒发送150多个包的速率持续发送同样的分段IP包给Windows系统(包括95/98/NT/win2000),
将导致受攻击主机的CPU占用率达到100%,网络接口和服务中断。当攻击停止时,服务会恢复正常。

<* 来源:BindView Security Advisory (tsabin@razor.bindview.com)
        Microsoft Security Bulletin (MS00-029)
*>


建议:
微软已经提供了针对这个问题的补丁程序,请根据系统从下列地址下载:

- Windows 95:
   http://download.microsoft.com/download/win95/update/8070/
   w95/EN-US/259728USA5.EXE
- Windows 98:
   http://download.microsoft.com/download/win98/update/8070/
   w98/EN-US/259728USA8.EXE
- Windows NT 4.0 Workstation, Server and Server, Enterprise
   Edition:
   http://www.microsoft.com/Downloads/Release.asp?ReleaseID=20829
- Windows NT 4.0 Server, Terminal Server Edition:
   http://www.microsoft.com/Downloads/Release.asp?ReleaseID=20830
- Windows 2000 Professional, Server and Advanced Server:
   http://www.microsoft.com/Downloads/Release.asp?ReleaseID=20827


浏览次数:6427
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障