Ssping patch not applied

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: ssping

Platforms: Windows NT
Description:

An unpatched version of Windows NT has been found. It is possible for an attacker to cause the host to crash by sending improperly formed ICMP packets.

Remedy:

Apply the teardrop2 patch.

To apply teardrop2, follow these steps:

  1. From the Windows NT Start menu, select Run.
  2. Type 'ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postSP3/teardrop2-fix/ and press Enter.
  3. View the README.TXT for patch version and execution.

For more information about teardrop2, see Microsoft Knowledge Base Article Q179129 available from ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postSP3/teardrop2-fix/Q179129.txt.

References:

Microsoft Knowledge Base Article Q154174, Invalid ICMP Datagram Fragments Hang Windows NT, Windows 95, http://support.microsoft.com/support/kb/articles/Q154/1/74.asp


X-Force Logo
Know Your Risks