The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-059: Unchecked Buffer in Universal Plug and Play can Lead to System Compromise
Time: 18:00 EST/23:00 GMT | News Source: ActiveWin.com | Posted By: Matthew Sabean

The Universal Plug and Play (UPnP) service allows computers to discover and use network-based devices. Windows ME and XP include native UPnP services; Windows 98 and 98SE do not include a native UPnP service, but one can be installed via the Internet Connection Sharing client that ships with Windows XP. This bulletin discusses two vulnerabilities affecting these UPnP implementations. Although the vulnerabilities are unrelated, both involve how UPnP-capable computers handle the discovery of new devices on the network.

The first vulnerability is a buffer overrun vulnerability. There is an unchecked buffer in one of the components that handle NOTIFY directives – messages that advertise the availability of UPnP-capable devices on the network. By sending a specially malformed NOTIFY directive, it would be possible for an attacker to cause code to run in the context of the UPnP service, which runs with System privileges on Windows XP. (On Windows 98 and Windows ME, all code executes as part of the operating system). This would enable the attacker to gain complete control over the system.

The second vulnerability results because the UPnP doesn’t sufficiently limit the steps to which the UPnP service will go to obtain information on using a newly discovered device. Within the NOTIFY directive that a new UPnP device sends is information telling interested computers where to obtain its device description, which lists the services the device offers and instructions for using them. By design, the device description may reside on a third-party server rather than on the device itself. However, the UPnP implementations don’t adequately regulate how it performs this operation, and this gives rise to two different denial of service scenarios.

Patch availability:

Write Comment
Return to News

  Displaying 301 through 308 of 308
Prev | First
  The time now is 4:29:29 AM ET.
Any comment problems? E-mail us
#301 By 4240821 (62.76.153.72) at 11/23/2024 6:19:10 PM
https://justpaste.me/CLhd3
https://justpaste.me/BoND2
https://justpaste.me/BucW3
https://justpaste.me/C8EX1
https://justpaste.me/Bih31
https://justpaste.me/Bzd42
https://justpaste.me/C1AO1
https://justpaste.me/CCQM
https://justpaste.me/BjCp2
https://justpaste.me/CED11

#302 By 4240821 (212.193.138.162) at 11/24/2024 9:16:13 AM
https://www.google.nu/amp/s/nsfw.su/get/a262/a262srrygohqoymeawz.php
https://www.google.ne/amp/s/lustful.su/get/a71/a71xtrrklbqaxqpihr.php
https://www.google.nr/amp/s/sexonly.su/get/a156/a156shiohxfljoqdajd.php
https://www.google.ne/amp/s/sexonly.su/get/a289/a289iprzpuotlvpdfyg.php
https://www.google.pk/amp/s/sluts.su/get/a18/a18kyvzbqmfwfubthf.php
https://www.google.nr/amp/s/lustful.su/get/a297/a297hmhjrrryokbmeee.php
https://www.google.nu/amp/s/sluts.su/get/a204/a204axwgnrfjpsnjdwx.php
https://www.google.mx/amp/s/sluts.su/get/a212/a212bmqigkjvqokzyeb.php
https://www.google.mx/amp/s/nsfw.su/get/a293/a293rejchngrcmuneth.php
https://www.google.ng/amp/s/sluts.su/get/a34/a34mdftdfompxopplp.php

#303 By 4240821 (62.76.153.72) at 11/24/2024 1:52:33 PM
https://justpaste.me/BcSI1
https://justpaste.me/C2wh3
https://justpaste.me/CCQM
https://justpaste.me/Bx0Z1
https://justpaste.me/Bvcm4
https://justpaste.me/C3go1
https://justpaste.me/Bmzw3
https://justpaste.me/Bb6H2
https://justpaste.me/CC4w
https://justpaste.me/CSoZ1

#304 By 4240821 (77.83.4.69) at 11/25/2024 12:20:15 PM
https://justpaste.me/BdV21
https://justpaste.me/CR541
https://justpaste.me/BjYF2
https://justpaste.me/C9Iq
https://justpaste.me/CSdQ1
https://justpaste.me/BaIY3
https://justpaste.me/Bw20
https://justpaste.me/CJLC3
https://justpaste.me/Bx0Z1
https://justpaste.me/CQjD2

#305 By 4240821 (212.193.138.162) at 11/25/2024 4:46:35 PM
https://www.google.ae/amp/s/sexonly.top/get/a0/a0oywwjtxgeqletof.php
https://www.google.ae/amp/s/lustful.su/get/a192/a192sjnjbirzpklsxaz.php
https://www.google.com/amp/s/lustful.su/get/a144/a144mfgxrsztqkqqjce.php
https://www.google.ad/amp/s/lustful.su/get/a96/a96qbudserehmkvecr.php
https://www.google.al/amp/s/lustful.su/get/a269/a269xmujhwrvwnqdrzq.php
https://www.google.ae/amp/s/sluts.su/get/a85/a85hyfxipjnuywrnti.php
https://www.google.ae/amp/s/sexonly.top/get/a30/a30xohjufhkpohvcqs.php
https://www.google.ad/amp/s/nsfw.su/get/a107/a107uxzpcohgrbjbevl.php
https://www.google.as/amp/s/sexonly.su/get/a250/a250yshewkmiutlbsum.php
https://www.google.am/amp/s/sexonly.top/get/a85/a85jqpelrkkmzclght.php

#306 By 4240821 (212.193.138.162) at 11/26/2024 6:08:32 AM
https://justpaste.me/CbMw1
https://justpaste.me/CQC0
https://justpaste.me/Cbsf3
https://justpaste.me/CIng4
https://justpaste.me/Bav21
https://justpaste.me/CaPQ4
https://justpaste.me/CKxb2
https://justpaste.me/Bdqk3
https://justpaste.me/CFRU2
https://justpaste.me/CZC31

#307 By 4240821 (77.83.4.69) at 11/26/2024 7:46:47 AM
https://www.google.sc/amp/s/sexonly.top/get/a168/a168ltmhwjmohcqkyix.php
https://www.google.pt/amp/s/lustful.su/get/a111/a111wwaiskxywmiblbf.php
https://www.google.ro/amp/s/sluts.su/get/a181/a181bvyeijfffjqxnhf.php
https://www.google.rs/amp/s/nsfw.su/get/a115/a115hvcfeclwektmjmk.php
https://www.google.rs/amp/s/sexonly.top/get/a133/a133jcdlujerwoyfotd.php
https://www.google.ro/amp/s/lustful.su/get/a264/a264ukqgvysehxnxgqi.php
https://www.google.rw/amp/s/lustful.su/get/a106/a106guoqtvntyighbum.php
https://www.google.pl/amp/s/sluts.su/get/a38/a38etguhbnuyencgca.php
https://www.google.pl/amp/s/sexonly.su/get/a25/a25kfopysqgukxxxyz.php
https://www.google.sc/amp/s/nsfw.su/get/a278/a278rfvhkdxfqylyrdu.php

#308 By 4240821 (80.73.244.53) at 11/27/2024 1:43:19 PM
https://www.google.vu/amp/s/sluts.su/get/a207/a207ffbgblydqwahtxo.php
https://www.google.to/amp/s/nsfw.su/get/a243/a243vkhnaevbpwiangc.php
https://www.google.us/amp/s/lustful.su/get/a230/a230jngmkzllhjxjbnr.php
https://www.google.vu/amp/s/nsfw.su/get/a98/a98jioafgyxnoplryz.php
https://www.google.vu/amp/s/lustful.su/get/a245/a245wioebwevrmhjsae.php
https://www.google.tl/amp/s/sexonly.top/get/a17/a17klzcrhhcicakgis.php
https://www.google.vu/amp/s/sexonly.top/get/a197/a197yxvibqgekscwefv.php
https://www.google.uz/amp/s/nsfw.su/get/a68/a68euldjqojdwmspmi.php
https://www.google.uz/amp/s/sluts.su/get/a270/a270srmontajsfwtzpg.php
https://www.google.vu/amp/s/nsfw.su/get/a252/a252mnfsalvjjzrazhj.php

Write Comment
Return to News
  Displaying 301 through 308 of 308
Prev | First
  The time now is 4:29:29 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *