Linked by Thom Holwerda on Sun 19th Nov 2006 19:08 UTC, submitted by Neti
Thread beginning with comment 184242
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[6]: The inevitable is happening
by stestagg on Wed 22nd Nov 2006 00:39
in reply to "RE[5]: The inevitable is happening"
Both allowed remote users to do stuff:
You mentioned 17, claiming that this was a big number. I was pointing out that at least 7 of those, were issues that are present (LOCAL user DOS) and unfixable in Windows XP (assuming default install (i.e. not with special privilege restrictions) - which we must when talking about security advisories)
It depends whether the user is a "User", "Power User" or "Administrator".
No. Users, Power Users and Administrators can DOS/Crash the System, without system patches, anyway.
RE[7]: The inevitable is happening
by NotParker on Wed 22nd Nov 2006 07:36
in reply to "RE[6]: The inevitable is happening"






Member since:
2006-06-01
A significant number of them were:
"allowed a local user to cause a denial of service attack."
Both allowed remote users to do stuff:
#1) "a remote user could cause a denial of service
(panic) by accessing socket buffers memory after freeing them."
#2) "allowed a remote user to cause a denial of service (crash) or potential memory corruption "
Several allow root escalation.
"Now forgive me if i'm wrong, but where in Windows XP can a user NOT cause a DOS / Superuser action / system format?"
It depends whether the user is a "User", "Power User" or "Administrator".