OSVDB ID: 26433

Title: Microsoft Windows TCP/IP Protocol Driver Source Routing Overflow

Info

Disclosure

Jun 13, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in Windows. The TCP/IP protocol driver fails to validate packets with an unspecified Source Routing flag resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Windows

2000 SP4
XP SP1
XP SP2

Windows Server

2003
2003 SP1
2003 for Itanium
2003 for Itanium SP1
2003 x64 Edition

References

Credit

  • Andrey Minaev - angel3000hotbox.ru -


Direct URL: http://osvdb.org/26433