SecureScoutLogo.jpg
oshare Attack Vulnerability



Go to Vulnerabilities List


General Info


TC: 12022
Description: It is possible to crash a Windows 9x computer by sending it a badly formed packet (named "oshare").
TC Impact: Crash



Specific Operations and Actions:


Vulnerability Publication: January 1999
Advisory Copyright: DEF CON ZERO WINDOW
Summary: Using a special malformed packet, an attacker can crash the system remotely.
Risk: High
CVSS 2.0 metrics: Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: Complete
CVSS 2.0 Base Score: 7.8
Vulnerability Impact: Crash
Host Impact: A malformed packet can crash the system
Nature of Remediation: Update OS.
Step required to fix the reported vulnerability:

***** Solution type: Upgrade Software *****

Upgrade to the latest version of Windows 98. See references for more details.



Glossary and References :


References:
* XF: win98-oshare-dos
http://xforce.iss.net/xforce/xfdb/2228
* MISC:
http://www.securityfocus.com/archive/1/12130
* MISC:
http://archives.neohapsis.com/archives/bugtraq/1999_1/0316.html
* MISC:
http://support.microsoft.com/ph/1139

CVE Link: CVE-1999-0357
CVE Compatible

Glossary: Crash
Packet
UDP


© 2003-2010 NexantiS Corporation (www.securescout.com)
SecureScout is a trademark of NexantiS
All Rights Reserved
All products names referenced herein are trademarks of their respective companies

SecureScout products are certified:
CVE Compatible
SANS TOP 20 Compatible
CVSS Compatible (Common Vulnerability Scoring System)