Secunia Logo
Netsikker nu! 2008
 
Microsoft Windows IGMP Denial of Service Vulnerability
Secunia Advisory: SA18853
Release Date: 2006-02-14
Last Update: 2007-10-24
Popularity: 15,262 views

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

OS:Microsoft Windows CE .NET 4.x
Microsoft Windows CE 5.0
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-0021


Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a validation error in the handling of IGMP requests. This can be exploited to cause a vulnerable system to stop responding by sending it a specially crafted IGMP packet.

Solution:
Apply patches.

Microsoft Windows XP SP1 / Microsoft Windows XP SP2:
http://www.microsoft.com/downloads/de...=7BB21D74-C37B-472B-BB10-71D4680680A7

Microsoft Windows XP Professional x64 Edition:
http://www.microsoft.com/downloads/de...=8E2538CC-CC90-4DB7-8D0B-0B8BA4234E67

Microsoft Windows Server 2003 and Microsoft Windows Server 2003 SP1:
http://www.microsoft.com/downloads/de...=78D7DF14-6049-4318-89CA-9C8681CED8AB

Microsoft Windows Server 2003 (Itanium) and Microsoft Windows Server 2003 SP1 (Itanium):
http://www.microsoft.com/downloads/de...=9AE276CF-AB46-4198-BCB3-3EFFDF15550E

Microsoft Windows Server 2003 x64 Edition:
http://www.microsoft.com/downloads/de...=12AAE69E-C5C3-4E4A-9970-F5DB84DD9744

Windows CE 4.2:
Fixed in September 2007 monthly update or upgrade to Windows CE 6.0.

Windows CE 5.0:
http://support.microsoft.com/kb/930642

Provided and/or discovered by:
The vendor credits Douglas Nascimento, Datacom.

Changelog:
2006-02-15: Added link to US-CERT vulnerability note.
2007-10-24: Updated affected software list and "Solution" section to include information on Windows CE as provided by Ollie Whitehouse, Symantec Research. Added additional link to Microsoft.

Original Advisory:
MS06-007 (KB913446):
http://www.microsoft.com/technet/security/Bulletin/MS06-007.mspx

KB930642:
http://support.microsoft.com/kb/930642

Other References:
US-CERT VU#839284:
http://www.kb.cert.org/vuls/id/839284


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

7th Oct, 2008
New advisories: 19
New vulnerabilities: 68
Updated advisories: 62

Moderately // 426 views
Debian update for php5
Moderately // 342 views
Atarone CMS Multiple Vulnerabilities
Moderately // 370 views
Debian update for squid
Less // 359 views
SUSE update for mercurial
Moderately // 411 views
SUSE update for openssh
Less // 333 views
Fedora update for mediawiki

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB Avatar Script Insertion Vulnerability // 80 views
2. phpBB Avatar Functions Information Disclosure and Deletion // 77 views
3. Debian update for php5 // 40 views
4. phpBB "url" bbcode Script Insertion Vulnerability // 36 views
5. Atarone CMS Multiple Vulnerabilities // 33 views
6. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 32 views
7. MetaGauge Directory Traversal Vulnerability // 32 views
8. Debian update for squid // 32 views
9. phpBB BBcode "url" Script Insertion Vulnerability // 30 views
10. SUSE update for openssh // 29 views