Windows 2000 SMTP Patch: Feb 27

All of these implementations contain a flaw that could enable denial of service attacks to be mounted against the service. The vulnerability results because the affected services don't perform this additional checking correctly.

A vulnerability results in both services because of a flaw in the way they handle a valid response from the NTLM authentication layer of the underlying operating system. Severity Rating: Low Internet ServersIntranet ServersClient Systems Windows 2000 LowLowLow Windows NT Server 4.0 LowLowLow Exchange Server 5.5 LowLowNone Mitigating factors: Windows XP Home Edition does not provide an SMTP service, and is not affected by the vulnerability.

A remote user can cause the SMTP service to crash. Frequently asked questions What's the scope of the vulnerability? Solution: The vendor has released a fix. The system returned: (22) Invalid argument The remote host or network may be down.

Clients who use the MAPI protocol (Outlook users) will not be affected. Revisions: V1.0 (February 27, 2002): Bulletin Created. Escape character is '^]'. 220 shattered Microsoft ESMTP MAIL Service, Version: 5.0.2195.3779 ready at Mon, 12 Nov 2001 23:33:28 -0600 HELO BISH 250 shattered Hello [] MAIL FROM: ERUSOLCSIDLLUF 250 If the attacker included the command at issue here within that data, the SMTP service on the system would fail.

Inclusion in future service packs: The fix for this issue will be included in Windows 2000 Service Pack 3 and Windows XP Professional Service Pack 1. Best practices recommend disabling unneeded services.

This vulnerability could enable an unauthorized user to consume resources of a mail server without authorization. The details and patch can be obtained from: * http://www.microsoft.com/technet/security/bulletin/MS02-012.asp The "exploit" for can be obtained from: * http://www.digitaloffense.net/mssmtp/mssmtp_dos.pl On February 12th, the SP2SR1 patch was released.

What would this enable the attacker to do? The Exchange Server 5.5 IMC, upon receiving notification from the NTLM authentication layer that a user has been authenticated, reportedly fail to perform the required additional checks before granting the user The fix for this issue will reportedly be included in Windows 2000 SP3 and Windows XP Professional SP1.

Previous versions are no longer supported, and may or may not be affected by these vulnerabilities. We appreciate your feedback. Yes, the Windows 2000 patch for both MS02-011 and MS02-012 are the same. A remote user could relay unauthorized mail via the system.

SMTP (Simple Mail Transfer Protocol) is an industry standard for delivery of mail via the Internet, defined in RFCs 2821 and 2822 . There is no charge for support calls associated with security patches. Click here to join today! get redirected here No, because Exchange 5.0 servers do not support allowing or disallowing mail relay based on authentication.

Windows 2000 Server, Professional and Advanced Server: http://www.microsoft.com/Downloads/Release.asp?ReleaseID= 36556 Windows NT Server 4.0: http://www.microsoft.com/downloads/details.aspx?FamilyId=457C0C18-8C3E-4923-B395-614C117F13C5&displaylang=en Exchange Server 5.5: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=33423 Windows 2000 Datacenter Server: Patches for Windows 2000 Datacenter Server are hardware-specific and

