涉及程序: Index Server 详细: 微软发布安全公告,指出 Index Server 2.0 存在两个漏洞: 1、缓冲区溢出漏洞 Index Server 2.0 的处理查询请求函数存在一个未经检查的缓冲。攻击者如果对受影响系统提供一个过长的请求将会导致缓冲区溢出,如果提供的是随机字符串,会导致服务器当机;如果提供一个精心构造的请求则能在服务器上执行任意代码。 2、泄露敏感信息漏洞 此漏洞影响 Index Server 2.0 和 Indexing Service in Windows 2000。该漏洞相似于 MS00-006 安全公告中的漏洞,当攻击者发送一个非法的查询请求时,它能获得 web 服务器的某些文件结构信息,这个信息有助于对目标机器实施攻击。 受影响系统: Microsoft Index Server 2.0 Indexing Service in Microsoft Windows 2000 解决方案: 请用户下载安装补丁(中文版) 一、Index Server 2.0: 缓冲区溢出漏洞: MS 下载:http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29660 CNNS 下载:http://www.cnns.net/frankie/mirror/download/CHSQ294472i.exe 泄露敏感信息漏洞: MS 下载:http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29631 二、Indexing Service in Windows 2000 professional,Server ,Advanced Server: MS 下载:http://www.microsoft.com/Downloads/Release.asq?ReleaseID=29561 三、Indexing Service in Windows 2000 Datacenter Server: Windows 2000 Datacenter Server 补丁与硬件相关,请与原始设备供应商联系