积极预防 及时发现
快速响应 力保恢复
KaZaA, Grokster和Morpheus是基于FastTrack P2P技术的文件共享客户端...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020045 CVE编号: 安全级别:高 漏洞中文描述: KaZaA, Grokster和Morpheus是基于FastTrack P2P技术的文件共享客户端,它们运行于Microsoft Windows平台,并已经移植到Linux平台。基于FastTrack P2P技术的文件共享客户端存在拒绝服务问题。反复的发送消息到运行有漏洞客户端的主机将会耗尽它的资源。虽然可以用客户端忽略恶意重复信息的特性来减轻这个漏洞的影响,但它还存在攻击者伪造身份的漏洞。基于FastTrack P3P技术的文件共享客户端如果有消息功能可能都会有这个漏洞。 漏洞英文描述: KaZaA, Grokster and Morpheus are file-sharing clients based on FastTrack P2P technologies. They will run on Microsoft Windows 9x/ME/NT/2000/XP systems. Ports also exist for variants of the Linux operating system. It has been reported that it is possible to starve resources on a host running a vulnerable client by repeatedly sending messages. While normally this issue could be mitigated by using the features provided by the client to ignore a malicious user who is repeatedly sending messages, it has been discovered that it is also possible for an attacker to spoof their identity. The identity spoofing issue is described in BugTraq 4121 "FastTrack P2P Technology Message Service Identity Spoofing Vulnerability". Any versions of file-sharing clients based on FastTrack P2P technologies which include the messaging functionality should be considered prone to this issue. This issue has reportedly been addressed in KaZaA v1.5. 漏洞参考: http://www.kazaa.com/en/index.htm 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:异常处理错误