积极预防 及时发现
快速响应 力保恢复
Windows系统的IIS服务器自带了一个SMTP服务器组件。Windows 2000和XP Pro...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020022 CVE编号:CAN-2002-0055 安全级别:高 漏洞中文描述: Windows系统的IIS服务器自带了一个SMTP服务器组件。Windows 2000和XP Professional SMTP服务在处理命令上存在问题,远程攻击者可能利用此漏洞对服务器程序实施拒绝服务攻击。Windows 2000和XP Professional SMTP服务处理某些种类的畸形命令时会出错,远程攻击者可以借此对服务器程序进行拒绝服务攻击,需要重启程序才能恢复正常功能。此漏洞不影响Exchange 5.6。 漏洞英文描述: It has been reported that the native Windows 2000 and XP Professional SMTP service encounters difficulties when attempting to handle certain types of malformed SMTP commands. A remote attacker may be able to exploit this condition to cause a denial of SMTP service. The vulnerable software must be restarted to regain normal functionality. 漏洞参考: http://www.microsoft.com/technet/security/bulletin/MS02-012.asp 系统类型: Win2000/NT 漏洞类型:设计错误