CVE-2002-0621
CVSS5.0
发布时间 :2002-07-03 00:00:00
修订时间 :2008-09-10 15:12:35
NMCO    

[原文]Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.


[CNNVD]Microsoft Commerce Server 2000 OWC包安装程序远程缓冲区溢出漏洞(MS02-033)(CNNVD-200207-050)

        
        Microsoft Commerce Server是一款Microsoft开发的构建、配置和分析电子商务站点的WEB服务器产品。
        Commerce Server使用的Office Web Components (OWC)包安装程序对用户提交数据缺少正确边界检查,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击。
        Commerce Server的Office Web Components (OWC)包安装程序实现存在缓冲区溢出,远程攻击者提交特殊构建的畸形数据给Office Web Components (OWC)包安装程序,可以导致Office Web Components (OWC)包安装程序进程崩溃,精心构建提交数据可能使其以Office Web Components (OWC)包安装程序进程的权限在系统上执行任意指令,一般是LocalSystem权限。
        

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: NONE [对系统的机密性无影响]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:microsoft:commerce_server:2000Microsoft commerce server 2000
cpe:/a:microsoft:commerce_server:2000:sp1Microsoft commerce_server 2000 sp1
cpe:/a:microsoft:commerce_server:2000:sp2Microsoft commerce_server 2000 sp2

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0621
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2002-0621
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200207-050
(官方数据源) CNNVD

- 其它链接及资源

http://www.microsoft.com/technet/security/bulletin/ms02-033.asp
(VENDOR_ADVISORY)  MS  MS02-033
http://www.securityfocus.com/bid/5108
(UNKNOWN)  BID  5108
http://www.osvdb.org/5172
(UNKNOWN)  OSVDB  5172
http://www.iss.net/security_center/static/9424.php
(UNKNOWN)  XF  mscs-owc-installer-bo(9424)

- 漏洞信息

Microsoft Commerce Server 2000 OWC包安装程序远程缓冲区溢出漏洞(MS02-033)
中危 边界条件错误
2002-07-03 00:00:00 2006-08-30 00:00:00
远程  
        
        Microsoft Commerce Server是一款Microsoft开发的构建、配置和分析电子商务站点的WEB服务器产品。
        Commerce Server使用的Office Web Components (OWC)包安装程序对用户提交数据缺少正确边界检查,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击。
        Commerce Server的Office Web Components (OWC)包安装程序实现存在缓冲区溢出,远程攻击者提交特殊构建的畸形数据给Office Web Components (OWC)包安装程序,可以导致Office Web Components (OWC)包安装程序进程崩溃,精心构建提交数据可能使其以Office Web Components (OWC)包安装程序进程的权限在系统上执行任意指令,一般是LocalSystem权限。
        

- 公告与补丁

        临时解决方法:
        如果您不能立刻安装补丁或者升级,CNNVD建议您采取以下措施以降低威胁:
        * 删除OWC包安装程序,OWC包安装程序在Windows下命令为BDOWC.EXE,存在在directory /Program Files/Microsoft Commerce Server/widgets/owc目录下。
        厂商补丁:
        Microsoft
        ---------
        Microsoft已经为此发布了一个安全公告(MS02-033)以及相应补丁:
        MS02-033:Unchecked Buffer in Profile Service Could Allow Code Execution in Commerce Server (Q322273)
        链接:
        http://www.microsoft.com/technet/security/bulletin/MS02-033.asp

        补丁下载:
         * Microsoft Commerce Server 2000:
        
        http://www.microsoft.com/Downloads/Release.asp?ReleaseID=39591

         * Microsoft Commerce Server 2002:
        
        http://www.microsoft.com/Downloads/Release.asp?ReleaseID=39550

- 漏洞信息

5172
Microsoft Commerce Server OWC Installer LocalSystem Arbitrary Code Execution
Remote / Network Access Input Manipulation
Loss of Integrity Workaround, Patch / RCS
Exploit Public Vendor Verified

- 漏洞描述

A remote overflow exists in Microsoft Commerce Server. Microsoft Commerce Server Office Web Component package installer fails to handle malformed data resulting in a buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code or DoS resulting in a loss of confidentiality, integrity, and/or availability.

- 时间线

2002-06-26 Unknow
Unknow Unknow

- 解决方案

Install Microsoft Patch Q322273, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): remove the OWC package installer. The OWC package installer is named BDOWC.EXE, found in the directory /Program Files/Microsoft Commerce Server/widgets/owc, and can be deleated.

- 相关参考

- 漏洞作者

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站