Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
BID:31420
Info
Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
| Bugtraq ID: | 31420 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-4295 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Julien Bedard |
| Vulnerable: |
Microsoft Windows Mobile 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
Microsoft Windows Mobile is prone to a denial-of-service vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this issue to crash a device running Windows Mobile, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Windows Mobile 6.0 is vulnerable; other versions may also be affected.
Microsoft Windows Mobile is prone to a denial-of-service vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this issue to crash a device running Windows Mobile, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Windows Mobile 6.0 is vulnerable; other versions may also be affected.
Exploit / POC
Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
The following exploit code is available:
An attacker can use readily available network utilities to exploit this issue.
The following exploit code is available:
Solution / Fix
Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
References:
References:
- Windows Mobile Homepage (Microsoft)