CVE-2003-0813 Information
Description
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request which causes one thread to use memory after it has been freed a different vulnerability than CVE-2003-0352 (Blaster/Nachi) CVE-2003-0715 and CVE-2003-0528 and as demonstrated by certain exploits against those vulnerabilities.
Reference
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011870.html http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011886.html http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011901.html http://marc.info/?l=bugtraq&m=106579825211708&w=2 http://marc.info/?l=bugtraq&m=106588827513795&w=2 http://marc.info/?l=ntbugtraq&m=106580303918155&w=2 http://www.kb.cert.org/vuls/id/547820 http://www.securityfocus.com/bid/8811 http://www.securitylab.ru/_exploits/rpc2.c.txt http://www.us-cert.gov/cas/techalerts/TA04-104A.html http://xforce.iss.net/xforce/alerts/id/155 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A893 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A894 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A900
Share on: