| PROBLEM: | There are several vulnerabilities in TCP/IP: 1) IP Validation; 2) ICMP Connection Reset Vulnerability; 3) ICMP Path MTU Vulnerability; 4) TCP Connection Reset Vulnerability; and 5) Spoofed Connection Request Vulnerability. |
| PLATFORM: | Tested Software and Security Update Download Locations: Affected Software: Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 Microsoft Windows XP 64-Bit Edition Service Pack 1 (Itanium) Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium) Microsoft Windows Server 2003 Microsoft Windows Server 2003 for Itanium-based Systems Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (ME) Review the FAQ section of this bulletin for details about these operating systems. SPARC Platform Solaris 7, 8, 9, 10 x86 Platform Solaris 7, 8, 9, 10 HP-UX B.11.00, B.11.04, B.11.11, B.11.22, B.11.23 running TCP/IP HP-UX B.11.11 and B.11.23 running TOUR (Transport Optional Upgrade Release) HP Tru64 UNIX 5.1B-3, 5.1B-2/PK4, 5.1A PK, 4.0G PK4, 4.0F PK8 |
| DAMAGE: | Could allow an attacker to send a specially crafted IP message to an affected systems. |
| SOLUTION: | Upgrade to the appropriate versions. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. Could cause the affected system to remotely execute code. However, attempts to exploit these vulnerabilities would most likely result in a Denial of Service. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/p-177.shtml |
| ORIGINAL BULLETIN: | Microsoft Security Bulletin MS05-019 (893066) |
| http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx | |
| ADDITIONAL LINKS: | Sun Alert ID: 101658 (formerly 57746) http://www.sunsolve.sun.com/search/document.do?assetkey=1-26-57746-1&searchclause=%22category:security%22%20%22availability,%20security%22 |
| Visit Hewlett Packard's Web Site for security bulletin: HPSBUX01164 / SSRT 4884 rev. 8 and HPSBTU01210 / SSRT4743 / SSRT4884 rev. 1 |
|
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2005-0048 CAN-2004-0790 CAN-2004-0230 CAN-2005-0688 |
REVISION HISTORY:
04/13/2005 - revised to add a link to Sun Alert ID: 57746 for SPARC Platform
Solaris 7, 8, 9, 10 and x86 Platform Solaris 7, 8, 9, and 10.
05/12/2005 - revised to note changes to Microsoft's Security Bulletin MS05-019 that
advises customers of the planned re-release of this update in
June. The June update focuses on resolving network connectivity
issues that some customers experienced after installing this
security update (MS05-019).
06/02/2005 - added a link to HP's Security Bulletin that provides updates
addressing the ICMP vulnerabilities described in CAN-2004-0790 and
CAN-2004-1060.
06/15/2005 - revised to update the changes Microsoft has made in MS05-019.
06/20/2005 - revised to note changes to HP's Security Bulletin HPSBUX01164,
SSRT4884 that includes additional vulnerable software versions
B.11.11 and B.11.23 running TOUR.
06/29/2005 - revised to note changes to HP's Security Bulletin HPSBUX01164,
SRT4884 where they have put out rev. 3 for PHNE_33159 is available
for B.11.11.
07/11/2005 - revised to note changed to HP's Security Bulletin HPSBUX01164,
SRT4884 where they have put out rev. 4 for PHNE_32606 is available
for B.11.13.
07/25/2005 - revised to note changed to HP's Security Bulletin HPSBUX01164,
SRT4884 where they have put out rev. 5 for PHNE_33395 is available
for B.11.00.
08/17/2005 - updated Security Bulletin HPSBUX01164 / SSRT4884, provides patches
for B.11.04.
10/05/2005 - to added a reference to HP Security Bulletin HPSBTU01210 /
SSRT4743 / SSRT4884 rev 1 that provides updated patches
for HP Tru64 UNIX 5.1B-3, 5.1B-2/PK4, 5.1A PK, 4.0G PK4, 4.0F PK8.
12/07/2005 - added a reference to HP's revisions to HPSBUX01164 / SSRT4884 that
announces the availability of TOUR 3.0.
12/01/2006 - updated to note that Sun Alert ID: 101658 (formerly 57746) updated
its Contributing Factors and Resolution sections
12/08/2006 - updated to note that Sun Alert ID: 101658 (formerly 57746) updated
its Contributing Factors and Resolution sections and changed its State to "Resolved"
[***** Start Microsoft Security Bulletin MS05-019 *****]
Microsoft Security Bulletin MS05-019
Vulnerabilities in TCP/IP Could Allow Remote Code Execution and Denial of Service (893066)
Issued: April 12, 2005
Updated: June 14, 2005
Version: 2.0
Summary
Who should read this document: Customers who use Microsoft Windows
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately.
Security Update Replacement: None.
Caveats: Microsoft Knowledge Base Article 893066 documents the currently known issues that customers
may experience when they install this security update. The article also documents recommended solutions for
these issues. For more information, see Microsoft Knowledge Base Article 893066.
Tested Software and Security Update Download Locations:
Affected Software:
Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000 Service Pack 4 Download the update
Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 Download the update
Microsoft Windows XP 64-Bit Edition Service Pack 1 (Itanium) Download the update
Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium) Download the update
Microsoft Windows Server 2003 Download the update
Microsoft Windows Server 2003 for Itanium-based Systems Download the update
Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition
(ME) Review the FAQ section of this bulletin for details about these operating systems.
Non-Affected Software:
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
Microsoft Windows XP Professional x64 Edition
The software in this list has been tested to determine whether the versions are affected. Other versions
either no longer include security update support or may not be affected. To determine the support life cycle
for your product and version, visit the Microsoft Support Lifecycle Web site.
General Information
Executive Summary:
This update resolves several newly-discovered, privately-reported and public
vulnerabilities. Each vulnerability is documented in this bulletin in its own
Vulnerability Details section.
An attacker who successfully exploited the most severe of these vulnerabilities
could take complete control of an affected system. An attacker could then
install programs; view, change, or delete data; or create new accounts with
full user rights. However, an attacker who successfully exploited the most
severe of these vulnerabilities would most likely cause the affected system to
stop responding.
We recommend that customers apply the update immediately.
Severity Ratings and Vulnerability Identifiers:
| Vulnerability Identifiers | Impact of Vulnerability | Windows 98, 98 SE, ME | Windows 2000 | Windows XP Service Pack 1 | Windows XP Service Pack 2 | Windows Server 2003 |
IP Validation Vulnerability - CAN-2005-0048 |
Remote Code Execution |
Not Critical |
Critical |
Critical |
None |
None |
ICMP Connection Reset Vulnerability - CAN-2004-0790 |
Denial of Service |
Not Critical |
Moderate |
Moderate |
Moderate |
Moderate |
ICMP Path MTU Vulnerability - CAN-2004-1060 |
Denial of Service |
Not Critical |
Moderate |
Moderate |
Moderate |
Moderate |
TCP Connection Reset Vulnerability - CAN-2004-0230 |
Denial of Service |
Not Critical |
Low |
Low |
None |
Low |
Spoofed Connection Request Vulnerability - CAN-2005-0688 |
Denial of Service |
None |
None |
None |
Low |
Low |
Aggregate Severity of All Vulnerabilities |
|
Not Critical |
Critical |
Critical |
Moderate |
Moderate |
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/