Flaw in Windows Function Could Allow Denial of Service New
A security flaw exists in a Windows NT 4.0 Server file management function that can cause a denial of service vulnerability.
Issue
The flaw results because the affected function can cause memory that it does not own to be freed when a specially crafted request is passed to it. If the application making the request to the function does not carry out any user input validation and allows the specially crafted request to be passed to the function, the function may free memory that it does not own. As a result, the application passing the request could fail.
By default, the affected function is not accessible remotely, however applications installed on the operating system that are available remotely may make use of the affected function. Application servers or Web servers are two such applications that may access the function. Note that Internet Information Server 4.0 (IIS 4.0) does not, by default, make use of the affected function.
Affected Products
- Microsoft Windows NT 4.0 Server
- Microsoft Windows NT 4.0 Terminal Server Edition
Download
Software patches are available from the following locations:
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: July 23, 2003
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<
















