|
Microsoft Windows Multiple IPv6 Denial of Service Vulnerabilities
|
|
Secunia Advisory:
|
SA22341
|
|
|
Release Date:
|
2006-10-10
|
|
Popularity:
|
9,609 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows XP Home Edition Microsoft Windows XP Professional
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2004-0230 CVE-2004-0790 CVE-2005-0688
|
|
Description: Three vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service).
1) A vulnerability exists in the IPv6 Windows implementation of ICMP which, if successfully exploited, results in the system dropping an existing connection.
2) A vulnerability exists in the IPv6 Windows implementation of TCP which, if successfully exploited, results in the system dropping an existing TCP connection.
3) A vulnerability exists in the IPv6 implementation of TCP/IP which, if successfully exploited, could cause the system to stop responding.
Successful exploitation of the vulnerabilities requires IPv6 to be configured (not enabled by default).
Solution: Apply patches.
Microsoft Windows XP SP1/SP2:
http://www.microsoft.com/downloads/de...=9fd73d12-ff7c-411d-944d-a6f147b20775
Microsoft Windows XP Professional x64 Edition:
http://www.microsoft.com/downloads/de...=fc98f55c-520e-4a68-a3c3-0df51c6122bb
Microsoft Windows Server 2003 (with or without SP1):
http://www.microsoft.com/downloads/de...=102591a0-2b58-497b-bc20-593571b96e9c
Microsoft Windows Server 2003 (Itanium, with or without SP1):
http://www.microsoft.com/downloads/de...=12515d47-134d-4d1f-9ae7-f0a7167ec424
Microsoft Windows Server 2003 x64 Edition:
http://www.microsoft.com/downloads/de...=c5faba34-48f5-4875-a0fa-6b8207f9b276
Provided and/or discovered by: Reported by the vendor.
Original Advisory: MS06-064 (KB922819):
http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|