Advertisement
Promo

Security threats Toolkit

Windows security hole and fix explained

Dave Wilby ZDNet.co.uk

Published: 09 Sep 1999 17:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Another software patch has been released by the Microsoft camp, this time for a glitch in the TCP/IP stack implementation of Windows 95 and 98.

The problem is caused by fragmented IGMP (Internet Group Management Protocol) packets, which can cause problems with the operating systems, up to and including a full machine crash.

IGMP is one of the protocols in the TCP/IP protocol suite, and is used to allow IP multicasting, in which data is sent to a single IP address but may reach multiple hosts.

The vulnerability can leave Windows users open to denial of service attacks. The effect of an attack can vary widely depending upon system loading and other factors, Microsoft said, but could result in minor slowdowns in system performance, loss of some networking functionality or a system crash.

In some cases, users could be protected from malicious attacks by some firewalls, desktop security, or, bizarrely, something as simple as a slow network connection that could give an affected machine time to recover from such an attack.

Windows NT 4.0 is also vulnerable, but includes additional system mechanisms that reduce susceptibility, although Microsoft believes that no Windows NT machines have been affected as yet, and indeed wouldn't succumb to attack under the company's own testing.

Microsoft failed to comment on the security hole, or the patch supplied to fix it.

Patches for Windows 98 and NT 4.0 are already available for download, with full support from Microsoft.

A patch for Windows 95 is promised before the end of the week.

Have you been affected by this security hole? Have you downloaded a patch just in case?

Tell the mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
55 out of 123 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:













Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters