The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-059: Unchecked Buffer in Universal Plug and Play can Lead to System Compromise
Time: 18:00 EST/23:00 GMT | News Source: ActiveWin.com | Posted By: Matthew Sabean

The Universal Plug and Play (UPnP) service allows computers to discover and use network-based devices. Windows ME and XP include native UPnP services; Windows 98 and 98SE do not include a native UPnP service, but one can be installed via the Internet Connection Sharing client that ships with Windows XP. This bulletin discusses two vulnerabilities affecting these UPnP implementations. Although the vulnerabilities are unrelated, both involve how UPnP-capable computers handle the discovery of new devices on the network.

The first vulnerability is a buffer overrun vulnerability. There is an unchecked buffer in one of the components that handle NOTIFY directives – messages that advertise the availability of UPnP-capable devices on the network. By sending a specially malformed NOTIFY directive, it would be possible for an attacker to cause code to run in the context of the UPnP service, which runs with System privileges on Windows XP. (On Windows 98 and Windows ME, all code executes as part of the operating system). This would enable the attacker to gain complete control over the system.

The second vulnerability results because the UPnP doesn’t sufficiently limit the steps to which the UPnP service will go to obtain information on using a newly discovered device. Within the NOTIFY directive that a new UPnP device sends is information telling interested computers where to obtain its device description, which lists the services the device offers and instructions for using them. By design, the device description may reside on a third-party server rather than on the device itself. However, the UPnP implementations don’t adequately regulate how it performs this operation, and this gives rise to two different denial of service scenarios.

Patch availability:

Write Comment
Return to News

  Displaying 551 through 555 of 555
Prev | First
  The time now is 12:02:31 AM ET.
Any comment problems? E-mail us
#551 By 4240821 (82.115.4.230) at 6/28/2025 11:44:40 PM
https://lustful.su/v/1vuoyq55vd7h.php
https://lustful.su/v/3y8lk34tmht7.php
https://sexonly.su/v/tq70t2rbln7m.php
https://nsfw.su/v/f0lq98b6ad1v.php
https://sexonly.top/v/m9j9uig5bcg5.php
https://sexonly.su/v/y0qgmmigx58w.php
https://sexonly.top/v/l38qacpnp08p.php
https://nsfw.su/v/t4ozr9r6p2oj.php
https://nsfw.su/v/brydwmqfbyni.php
https://nsfw.su/v/gpkp6yyex55c.php

#552 By 4240821 (82.115.4.230) at 6/29/2025 4:58:14 PM
https://namethatpornstar.com/thread/4251362
https://namethatpornstar.com/thread/4253025
https://namethatpornstar.com/thread/4252209
https://namethatpornstar.com/thread/4251765
https://namethatpornstar.com/thread/4253036
https://namethatpornstar.com/thread/4252209
https://namethatpornstar.com/thread/4251362
https://namethatpornstar.com/thread/4251923
https://namethatpornstar.com/thread/4252214
https://namethatpornstar.com/thread/4251641

#553 By 4240821 (82.115.4.230) at 6/30/2025 10:55:43 AM
https://sluts.su/g/p31/p31zuwqhdbuxmqkrxv.php
https://sluts.su/g/p61/p61ezadsibzutnivgs.php
https://sexonly.su/g/p13/p13gvjqioggebrvxcj.php
https://nsfw.su/g/p28/p28gzuldifvlfsnisu.php
https://sexonly.top/g/p97/p97twbanssnoktkmio.php
https://sexonly.su/g/p44/p44tyuqyvqnvotlfbq.php
https://lustful.su/g/p50/p50yhttgnoeluuhsnh.php
https://nsfw.su/g/p33/p33gyzaxvsjsyriuql.php
https://sluts.su/g/p65/p65mdajveoezuajioi.php
https://sexonly.top/g/p52/p52crmtsmtedqeriku.php

#554 By 4240821 (82.115.4.230) at 7/1/2025 3:48:31 AM
https://lustful.su/g/p22/p22qbvbmpjirjhuprx.php
https://sexonly.su/g/p90/p90mivbuvptqlpiyyx.php
https://sexonly.top/g/p20/p20zgiqbapytyapawi.php
https://nsfw.su/g/p25/p25tewwcxdbqfxnoqx.php
https://sexonly.top/g/p27/p27gwloixkjkszffyi.php
https://sluts.su/g/p17/p17hwqxcizifgmhxbq.php
https://lustful.su/g/p37/p37zrijolyhtmfwknr.php
https://nsfw.su/g/p35/p35xvyksjlbqeidwxn.php
https://sexonly.su/g/p56/p56bvlwoezzoxuwiyz.php
https://nsfw.su/g/p71/p71xmzcgfxqtpouwid.php

#555 By 4240821 (82.115.4.230) at 7/1/2025 6:12:05 PM
https://lustful.su/g/p40/p40qpltspvofsqtnlz.php
https://sexonly.top/g/p97/p97weacurwejxkmxzn.php
https://sluts.su/g/p53/p53xdxbecnhhvmvkpu.php
https://sexonly.top/g/p26/p26gdnjudncmzyqzaw.php
https://nsfw.su/g/p37/p37ovyfucsvwcoyyjb.php
https://lustful.su/g/p58/p58brnydueicpijmmv.php
https://sluts.su/g/p17/p17iqvxtupcdlrqlpf.php
https://sluts.su/g/p14/p14vfndregwxsktrru.php
https://sexonly.su/g/p89/p89lsriwekakygxddk.php
https://nsfw.su/g/p35/p35yhvdloneafkeskf.php

Write Comment
Return to News
  Displaying 551 through 555 of 555
Prev | First
  The time now is 12:02:31 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *