ID

VAR-201010-0502


TITLE

Microsoft Windows Mobile Overly Long vCard Name Field Denial of Service Vulnerability

Trust: 0.3

sources: BID: 44287

DESCRIPTION

Microsoft Windows Mobile is prone to a denial-of-service vulnerability because it fails to adequately validate user-supplied input. An attacker can exploit this issue to crash a device running Windows Mobile, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed. Windows Mobile versions 6.1 and 6.5 are vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 44287

AFFECTED PRODUCTS

vendor:microsoftmodel:windows mobilescope:eqversion:6.5

Trust: 0.3

vendor:microsoftmodel:windows mobilescope:eqversion:6.1

Trust: 0.3

vendor:htcmodel:touch proscope:eqversion:2

Trust: 0.3

vendor:htcmodel:touch proscope:eqversion:0

Trust: 0.3

sources: BID: 44287

THREAT TYPE

network

Trust: 0.3

sources: BID: 44287

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 44287

EXTERNAL IDS

db:BIDid:44287

Trust: 0.3

sources: BID: 44287

REFERENCES

url:http://blog.securityarchitect.org/

Trust: 0.3

url:http://www.microsoft.com/windowsmobile/default.mspx

Trust: 0.3

sources: BID: 44287

CREDITS

Celil ?nĂ¼ver from SecurityArchitect.Org

Trust: 0.3

sources: BID: 44287

SOURCES

db:BIDid:44287

LAST UPDATE DATE

2022-05-17T02:03:36.710000+00:00


SOURCES UPDATE DATE

db:BIDid:44287date:2010-10-21T00:00:00

SOURCES RELEASE DATE

db:BIDid:44287date:2010-10-21T00:00:00