CVE-2002-1191
CVSS5.0
发布时间 :2002-10-28 00:00:00
修订时间 :2016-10-17 22:24:34
NMCOS    

[原文]The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.


[CNNVD]Sabre Desktop Reservation Software远程拒绝服务漏洞(CNNVD-200210-289)

        
        Sabre Desktop Reservation Software是一款桌面预定系统,可以用于旅行社和航空票务中心做预定工作。
        Sabre桌面预定系统的sabserv组件存在问题,远程攻击者可以利用这个漏洞进行拒绝服务攻击。
        Sabre桌面预定系统的sabserv组件监听TCP 1001端口,用于与客户端应用程序通信和连接Sabre本地网关。如果攻击者发送任意数据到sabserv组件监听TCP 1001端口,就会导致Sabserv停止与客户端通信1分钟,多次大量的这种连接可以导致产生拒绝服务攻击。
        

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1191
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2002-1191
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200210-289
(官方数据源) CNNVD

- 其它链接及资源

http://marc.info/?l=bugtraq&m=103478372603106&w=2
(UNKNOWN)  IDEFENSE  20021016 Denial of Service in Sabre Desktop Reservation Client for Windows
http://www.idefense.com/advisory/10.16.02.txt
(UNKNOWN)  MISC  http://www.idefense.com/advisory/10.16.02.txt
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=48
(UNKNOWN)  IDEFENSE  20021010 Denial of Service in Sabre Desktop Reservation Client for Windows
http://www.iss.net/security_center/static/10378.php
(VENDOR_ADVISORY)  XF  sabre-sabserv-client-dos(10378)
http://www.securityfocus.com/bid/5974
(UNKNOWN)  BID  5974

- 漏洞信息

Sabre Desktop Reservation Software远程拒绝服务漏洞
中危 其他
2002-10-28 00:00:00 2005-10-20 00:00:00
远程  
        
        Sabre Desktop Reservation Software是一款桌面预定系统,可以用于旅行社和航空票务中心做预定工作。
        Sabre桌面预定系统的sabserv组件存在问题,远程攻击者可以利用这个漏洞进行拒绝服务攻击。
        Sabre桌面预定系统的sabserv组件监听TCP 1001端口,用于与客户端应用程序通信和连接Sabre本地网关。如果攻击者发送任意数据到sabserv组件监听TCP 1001端口,就会导致Sabserv停止与客户端通信1分钟,多次大量的这种连接可以导致产生拒绝服务攻击。
        

- 公告与补丁

        厂商补丁:
        Sabre
        -----
        目前厂商还没有提供补丁或者升级程序,不过供应商已经声明将在下一个维护版本中修补这个漏洞,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:
        
        http://www.sabre.com

- 漏洞信息

6555
Sabre Desktop Reservation Software Sabserv Client TCP Port 1001 DoS
Local Access Required, Remote / Network Access Denial of Service
Loss of Availability
Exploit Public

- 漏洞描述

Sabre Desktop Reservation software contains a flaw that may allow a local or remote denial of service. The issue is triggered when a malformed packet is sent to TCP port 1001, and will result in loss of availability for the Sabre Desktop Reservation software.

- 时间线

2002-10-10 Unknow
2002-10-08 Unknow

- 解决方案

The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem. It is recommended that an alternate software package be used in its place.

- 相关参考

- 漏洞作者

- 漏洞信息

Sabre Desktop Reservation Software Client Denial Of Service Vulnerability
Failure to Handle Exceptional Conditions 5974
Yes No
2002-10-16 12:00:00 2009-07-11 06:06:00
Discovery of this issue is credited to Altomo <adame780@bellsouth.net>.

- 受影响的程序版本

Sabre Desktop Reservation Software 4.4 G

- 漏洞讨论

Sabre Desktop Reservation Software is prone to a denial of service condition. It is possible to trigger this condition by sending malformed data to the Sabserv component, which listens on TCP port 1001. Sabserv is used to facilitate connections by the client software.

This condition may be exploited to deny service to the client software.

- 漏洞利用

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com &lt;mailto:vuldb@securityfocus.com&gt;.

- 解决方案

The vendor has reportedly stated that the vulnerable component (Sabserv) of Sabre Desktop Reservation Software for Windows will be fixed in the next maintenance release.

- 相关参考

     

     

    关于SCAP中文社区

    SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

    版权声明

    CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站