A remote overflow exists in Windows XP. The Universal Plug and Play component fails to proper check boundary conditions when parsing certain HTTP headers resulting in a stack-based overflow. With a specially crafted HTTP request, an attacker can cause code execution with Local Service privileges resulting in a loss of integrity.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.