Microsoft ListBox/ComboBox Control User32.dll函数缓冲区溢出漏洞发布时间:2003-10-15 更新时间:2003-10-15 严重程度:高 威胁程度:普通用户访问权限 错误类型:边界检查错误 利用方式:客户机模式 BUGTRAQ ID:8827 CVE(CAN) ID:CAN-2003-0659 受影响系统 Microsoft Windows 2000 Advanced Server SP4详细描述 发送LB_DIR消息给listbox或者CB_DIR给combobox,指定超长路径名作为参数,可出现如下事件日志消息: ------------------------------------------------------------------------ Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7031 Description: The [application] service terminated unexpectedly. ------------------------------------------------------------------------ 在win2000中,工具管理器运行在本地系统帐户权限下,包含listbox control接收非特权用户的消息,如果本地用户发送带有超长路径名的消息,可使在wcscpy函数中出现异常,可能以高权限执行任意代码。 解决方案 补丁下载: Microsoft Windows 2000 Advanced Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Datacenter Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Professional SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Professional SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Advanced Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Datacenter Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=379F234D-CE7E-4897-8D29-0764997F1E42&displaylang=en Microsoft Windows 2000 Advanced Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=01358EAC-F1C5-4CB7-BE3D-64459F4AD3FD&displaylang=en Microsoft Windows 2000 Datacenter Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=01358EAC-F1C5-4CB7-BE3D-64459F4AD3FD&displaylang=en Microsoft Windows 2000 Professional SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=01358EAC-F1C5-4CB7-BE3D-64459F4AD3FD&displaylang=en Microsoft Windows 2000 Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=01358EAC-F1C5-4CB7-BE3D-64459F4AD3FD&displaylang=en Microsoft Windows XP Home SP1: Microsoft Patch Security Update for Microsoft Windows XP: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=ABC764AC-5B7B-4B99-BF3E-F57352E4C507&displaylang=en Microsoft Windows XP Professional SP1: Microsoft Patch Security Update for Microsoft Windows XP: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=ABC764AC-5B7B-4B99-BF3E-F57352E4C507&displaylang=en Microsoft Windows XP 64-bit Edition SP1: Microsoft Patch Security Update for Microsoft Windows XP 64-bit Edition: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=3E7B03BF-2231-4069-B76F-0BD69CF6E1D9&displaylang=en Microsoft Windows XP Embedded SP1: Microsoft Patch Security Update for Microsoft Windows XP: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=ABC764AC-5B7B-4B99-BF3E-F57352E4C507&displaylang=en Microsoft Windows Server 2003 Enterprise Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=02F97DE4-29DF-4D33-A33B-E7630349E69E&displaylang=en Microsoft Windows Server 2003 Datacenter Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=02F97DE4-29DF-4D33-A33B-E7630349E69E&displaylang=en Microsoft Windows Server 2003 Web Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=02F97DE4-29DF-4D33-A33B-E7630349E69E&displaylang=en Microsoft Windows Server 2003 Enterprise Edition 64-bit : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=E4BD7C05-EA0E-49C7-9BDD-ABB496CA87CA&displaylang=en Microsoft Windows Server 2003 Datacenter Edition 64-bit : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=E4BD7C05-EA0E-49C7-9BDD-ABB496CA87CA&displaylang=en Microsoft Windows XP 64-bit Edition Version 2003 : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=E4BD7C05-EA0E-49C7-9BDD-ABB496CA87CA&displaylang=en Microsoft Windows XP 64-bit Edition : Microsoft Patch Security Update for Microsoft Windows XP 64-bit Edition: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=3E7B03BF-2231-4069-B76F-0BD69CF6E1D9&displaylang=en Microsoft Windows Server 2003 Standard Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=02F97DE4-29DF-4D33-A33B-E7630349E69E&displaylang=en Microsoft Windows NT Server 4.0 SP6a: Microsoft Patch Security Update for Microsoft Windows NT Server 4.0: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=F3E87075-AAE5-49F4-9D37-24A116296188&displaylang=en Microsoft Windows NT Workstation 4.0 SP6a: Microsoft Patch Security Update for Microsoft Windows NT Workstation 4.0: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=5EA88ABE-8D53-4E25-959C-E80EB5FD7A91&displaylang=en Microsoft Windows NT Terminal Server 4.0 SP6: Microsoft Patch Security Update for Microsoft Windows NT Server Terminal Server Edition: KB824141 http://www.microsoft.com/downloads/details.aspx?FamilyId=0ADC8D90-2355-49A0-976B-57281B4521C1&displaylang=en 相关信息 参考:http://www.securityfocus.com/archive/1/341454 http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-045.asp |