20020822 CORE-20020618: Vulnerabilities in Windows SMB (DoS)mailing list
http://marc.info/?l=bugtraq&m=103011556323184&w=2 CVE-2002-0724
Microsoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (1)
Record summary
CVE-2002-0724 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMicrosoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (1)ExploitDB exploitby Frederic DeletangNot analyzed1 file
ExploitDBMicrosoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (2)ExploitDB exploitby zamolx3Not analyzed1 file
References
7VU#250635Third-party advisory
http://www.kb.cert.org/vuls/id/250635 VU#311619Third-party advisory
http://www.kb.cert.org/vuls/id/311619 VU#342243Third-party advisory
http://www.kb.cert.org/vuls/id/342243 MS02-045Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-045 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0724 oval:org.mitre.oval:def:189vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A189