Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13145
HistoryJun 14, 2006 - 12:00 a.m.

Server crash on ICMP packets with Loose Source and Record Route IP options.

2006-06-1400:00:00
vulners.com
15

Short message translation:

There are DoS conditions in Windows 2000 built-in NAT server. Tested
configuration: Windows 2000 English Standard/Advanced Service Pack 4 +
Update Rollup 1 for Service Pack 4 with NAT server enabled. While
routing packets with options "Loose Source and Record Route" defined by
RFC 791 through server, Windows crashes to BSOD with error in tcpip.sys
or ntoskrnl.exe, or system hangs or system began instable work. It
doesn't metter if packets are from internal or external networks. Use
attached script to test vulnerability. On Windows 2003 problem doesn't
present. It's also likely same problem to present in Windows 2000 + ISA
2000.