Microsoft Windows Help And Support Center URI处理缓冲区溢出问题发布时间:2003-10-15 更新时间:2003-10-15 严重程度:中 威胁程度:普通用户访问权限 错误类型:边界检查错误 利用方式:客户机模式 BUGTRAQ ID:8828 CVE(CAN) ID:CAN-2003-0711 受影响系统 Microsoft Windows 2000 Advanced Server SP4详细描述 Microsoft Windows 2003 Server和Windows XP提供支持和问题解决套件,称为PCHealth,提供用户怎样处理问题的方法。 PCHealth系统可以有多种方法启动,可以通过使用HCP协议或者DCOM在IE或OUTLOOK中通过HTML文档启动。由svchost.exe启动的Help service(helpsvc.exe)存在一个基于栈的缓冲区溢出,可通过提交超长查询来触发。可能以用户权限在系统上执行任意代码。 解决方案 补丁下载: Microsoft Windows 2000 Advanced Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=C2AB63FD-35CA-4D33-9F8C-8BF5DE2D1117&displaylang=en Microsoft Windows 2000 Professional SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=C2AB63FD-35CA-4D33-9F8C-8BF5DE2D1117&displaylang=en Microsoft Windows 2000 Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=C2AB63FD-35CA-4D33-9F8C-8BF5DE2D1117&displaylang=en Microsoft Windows 2000 Professional SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=C2AB63FD-35CA-4D33-9F8C-8BF5DE2D1117&displaylang=en Microsoft Windows 2000 Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=C2AB63FD-35CA-4D33-9F8C-8BF5DE2D1117&displaylang=en Microsoft Windows 2000 Advanced Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=C2AB63FD-35CA-4D33-9F8C-8BF5DE2D1117&displaylang=en Microsoft Windows 2000 Advanced Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=62B23A0C-67F0-4F11-A95E-E4FB080A63C6&displaylang=en Microsoft Windows 2000 Datacenter Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=62B23A0C-67F0-4F11-A95E-E4FB080A63C6&displaylang=en Microsoft Windows 2000 Professional SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=62B23A0C-67F0-4F11-A95E-E4FB080A63C6&displaylang=en Microsoft Windows 2000 Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=62B23A0C-67F0-4F11-A95E-E4FB080A63C6&displaylang=en Microsoft Windows XP Home SP1: Microsoft Patch Security Update for Microsoft Windows XP: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=84317458-0BEB-4B2C-A095-66CA09DFDAC6&displaylang=en Microsoft Windows XP Professional SP1: Microsoft Patch Security Update for Microsoft Windows XP: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=84317458-0BEB-4B2C-A095-66CA09DFDAC6&displaylang=en Microsoft Windows XP 64-bit Edition SP1: Microsoft Patch Security Update for Microsoft Windows XP 64-bit Edition: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=97F4868A-5E41-4657-B9FC-7EA13954B982&displaylang=en Microsoft Windows Server 2003 Standard Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=40F25862-A815-4674-9175-E3640E3EFD49&displaylang=en Microsoft Windows Server 2003 Enterprise Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=40F25862-A815-4674-9175-E3640E3EFD49&displaylang=en Microsoft Windows Server 2003 Web Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=40F25862-A815-4674-9175-E3640E3EFD49&displaylang=en Microsoft Windows Server 2003 Enterprise Edition 64-bit : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition: KB828035 http://www.microsoft.com/downloads/details.aspx?FamilyId=8B990946-84C8-4C91-899C-5A44EC13174E&displaylang=en Microsoft Windows Server 2003 64-bit Edition Microsoft Windows XP 64-bit Edition Version 2003 : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition: KB828035 http://www.microsoft.com/downloads/details.aspx?FamilyId=8B990946-84C8-4C91-899C-5A44EC13174E&displaylang=en Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows ME : Microsoft Patch Security Update for Microsoft Windows ME: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=7D6F4228-0E31-4F46-9795-5CDD566BB3B8&displaylang=en Microsoft Windows NT Enterprise Server 4.0 SP6a: Microsoft Patch Security Update for Microsoft Windows NT Server 4.0: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=735602AC-BA6E-40D4-8A20-3441F02A25CB&displaylang=en Microsoft Windows NT Server 4.0 SP6a: Microsoft Patch Security Update for Microsoft Windows NT Server 4.0: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=735602AC-BA6E-40D4-8A20-3441F02A25CB&displaylang=en Microsoft Windows NT Workstation 4.0 SP6a: Microsoft Patch Security Update for Microsoft Windows NT Workstation 4.0: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=88BCDC9A-E370-47D8-B818-4E659C7F95AE&displaylang=en Microsoft Windows NT Terminal Server 4.0 SP6: Microsoft Patch Security Update for Microsoft Windows NT Server Terminal Server Edition: KB825119 http://www.microsoft.com/downloads/details.aspx?FamilyId=5C16FFAB-9CE7-4444-9AA5-BC6ABE3FD479&displaylang=en 相关信息 David Litchfield of Next Generation Security Software Ltd. 参考:http://www.securityfocus.com/advisories/5979 http://www.ngssoftware.com/advisories/ms-pchealth.txt http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-044.asp |