New OOB Hotfix available

Danny Mayer ( )
Fri, 23 May 1997 10:16:49 -0400

For those who haven't heard, Microsoft has now released a new version
of the OOB fix (it was made available late Thursday evening - May 22).
According to the KB article:

DOCUMENT:Q143478 [winnt]
TITLE :Stop 0A in TCPIP.SYS When Receiving Out Of Band (OOB) Data
PRODUCT :Microsoft Windows NT
PROD/VER:3.51 4.00
KEYWORDS:kbbug3.51 kbbug4.00 kbfile kbfix3.51 kbfix4.00 NTSrvWkst nttcp

The information in this article applies to:

- Microsoft Windows NT Workstation versions 3.51 and 4.0
- Microsoft Windows NT Server versions 3.51 and 4.0


A Stop 0x0000000A occurs in Tcpip.sys when receiving Out of Band (OOB)


A sender specifies "Out of Band" data by setting the URGENT bit flag in the
TCP header. The receiver uses the URGENT POINTER to determine where in the
segment the urgent data ends. Windows NT bugchecks when the URGENT POINTER
points to the end of the frame and no normal data follows. Windows NT
expects normal data to follow.


Microsoft has updated Tcpip.sys to correct the problem. Instructions for
installing it are available from Microsoft support channels, or directly
from the following Internet locations:

** NOTE: This hotfix was originally posted on 5/12/97. A second fix **
** was completed on 5/21/97, to address another nearly identical **
** attack, and this hotfix has replaced the original one. **
** The first hotfix is included in 4.0 SP3, however the second one **
** is not, so a 4.0 post-sp3 is now available also. **


They have made hotfixes available for the following versions of NT and

NT 4.0 SP3 Intel and Alpha
NT 4.0 SP2 Intel
NT 3.51 SP5 Intel and Alpha

I'm trying to find out why there's no Alpha version for NT 4.0 SP2.


Danny Mayer Digital Equipment Corporation Marlboro, MA 01752