PDA

View Full Version : Microsoft Windows CE IGMP Denial of Service



newsbot
25-10-2007, 10:32 PM
This issue was originally discovered by Douglas Nascimento of Datacom and published in Microsoft security bulletin MS06-007 on February 14th 2006 and subsequently updated March 17th 2006. A condition exists with the Microsoft IP stack wherein a specially crafted IGMP packet causes a denial of service condition. In Microsoft's original advisory, Windows CE was omitted as a vulnerable platform; however, In Symantec's testing it was discovered that Windows CE 5.01 (shipped as part of the Windows Mobile 5 PocketPC and SmartPhone editions) is vulnerable. Symantec notified Microsoft in Feburary 2006 of the fact that CE was affected with Microsoft releasing a patch in KB930642 in February 2007.

http://www.securiteam.com/windowsntfocus/6C00N1FK0I.html