Does anyone have any updates? Or is there a Microsoft fix applicable/available to this problem:
Microsoft SMS
A vulnerability was reported in the Microsoft Systems Management Server (SMS) client software. A remote user can cause denial of service conditions.
Impact: Denial of service via network
QUESTION POSED ON: 17 JUL 2003
QUESTION ANSWERED BY: Rod Trent
As of a couple days ago, Microsoft was working hard to get a fix developed. I expect a patch to be released very soon.
As an aside…is it just me? Or does it seem like HexView is trying to make a name for themselves (and a little cash), instead of being responsible about notifying the vendor prior to public notification? Nice racket. And I guess it goes without saying that Symantec needs to be a bit more responsible about letting posts like that filter through (Symantec acquired Security Focus). Here's the original post.
I notice your link to Security Tracker indicates that the vendor was notified. The actuality is that HexView did not notify Microsoft about it (read the Vendor Status section in the original Security Focus posting). Microsoft was notified after-the-fact by those reading the original post.
|