int(4114)

Vulnerability Bulletins


Envenenamiento de la caché en Microsoft Windows DNS Server

Vulnerability classification

Property Value
Confidence level Oficial
Impact Integridad
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Windows 2000 SP4
Microsoft Windows XP SP2 y SP3
Microsoft Windows Server 2003 SP1 y SP2
Microsoft Windows Server 2008

Description

Se ha descubierto una vulnerabilidad en Windows 2000 SP4, XP SP2 y SP3, Server 2008 y Server 2003 SP1 y SP2. La vulnerabilidad reside en un error no especificado en el servidor DNS de Microsoft Windows.

Un atacante remoto podría enviar respuestas DNS especialmente diseñadas a consultas DNS, pudiendo redirigir el tráfico de Internet, mediante un ataque de envenenamiento de caché.

Solution



Actualización de software

Microsoft (MS08-037)
Windows 2000 SP4 / Servidor DNS / patch Windows2000-kb951746-x86-enu
Windows 2000 SP4 / Cliente DNS / patch Windows2000-kb951748-x86-enu
Windows XP SP2 y SP3 / patch Windowsxp-kb951748-x86-enu
Windows XP SP2 y SP3 / x64 / patch WindowsServer2003.WindowsXP-kb951748-x86-enu
Windows Server 2003 SP1 y SP2 / Servidor DNS / x32 / patch Windowsserver2003-kb951746-x86-enu
Windows Server 2003 SP1 y SP2 / Cliente DNS / x32 / patch Windowsserver2003-kb951748-x86-enu
Windows Server 2003 SP1 y SP2 / Servidor DNS / x64 / patch Windowsserver2003.WindowsXP-kb951746-x64-enu
Windows Server 2003 SP1 y SP2 / Cliente DNS / x64 / patch Windowsserver2003.WindowsXP-kb951748-x64-enu
Windows Server 2003 SP1 y SP2 / Servidor DNS / ia64 / patch Windowsserver2003-kb951746-ia64-enu
Windows Server 2003 SP1 y SP2 / Cliente DNS / ia64 / patch Windowsserver2003-kb951748-ia64-enu
http://www.microsoft.com/downloads

Standar resources

Property Value
CVE CVE-2008-1454
BID 30132

Other resources

Microsoft Security Bulletin (MS08-037)
http://www.microsoft.com/technet/security/Bulletin/MS08-037.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2008-07-18