
Universal Plug and Play Vulnerabilities Discovered
Latest Industry News: - Microsoft
- Free Tool Hunts Bots
- Found
- RPI, Law School Team to Offer Degrees in Tech Business Law
- Adobe's 2Q Profit Surges 24 Percent
- Duke: iPhone Not To Blame
- Cisco Closes the Books on Still Another Acquisition
- Microsoft Deal Values Facebook at $15B
- Netcraft
- Intel Unveils Low-Power Chip for 2-Way Blades
- Cisco Introduces New CallManager Security Features
- Special Report: Meta happens!
- You Move Me
- OS X Upgrade, IPhone May Boost Mac Sales
- CoSort 9 Eases Large XML/LDIF Conversion, Manipulation, Protection
- Appearance of Exploit Code Means Time Is Running Out to Apply Critical Windows Patch
- Vista Still Getting Mixed Reviews
- ISM’s PerfMan Grants IT Control over E-commerce Systems
- Making Amends
- Just What You Needed
Microsoft warned users Thursday to a critical vulnerability, the universal plug-and-play services, it may lead to system compromise, several software companies in the client operating system.
Windows XP and in Windows Me are vulnerable because of their native support for Universal Plug and Play (UPnP) service, which will allow computers to discover and use Web-based equipment. Windows Me, but these services are turned off by default. Windows 98 and Windows more affected, because such services in these operating systems can be installed from the Internet Connection Sharing client, ships with Windows XP.
Windows NT Workstation and Windows 2000 Professional Edition are not affected, according to the notice, because they do not support the UPnP.
Two unrelated flaw affects UPnP against by the new patch.
First is the buffer overflow handling components in the provision of e-mail advertisements UPnP-enabled devices on the network.
Second weakness from the Universal Plug and Play the failure to limit measures, the service will be taken to obtain information from a newly discovered device, making the system vulnerable to denial-of-service of the two.
Microsoft pointed out that the standard firewall, such as blocking port from 1900 to 5000, will protect corporate networks from Internet-based attacks. The company also said that the Internet Connection Firewall by default in Windows XP operating makes it harder to attack the use of the method.
This is the 59th security bulletin, Microsoft issued in 2001. Microsoft credited eEye Digital Security on this issue.
Windows XP and in Windows Me are vulnerable because of their native support for Universal Plug and Play (UPnP) service, which will allow computers to discover and use Web-based equipment. Windows Me, but these services are turned off by default. Windows 98 and Windows more affected, because such services in these operating systems can be installed from the Internet Connection Sharing client, ships with Windows XP.
Windows NT Workstation and Windows 2000 Professional Edition are not affected, according to the notice, because they do not support the UPnP.
Two unrelated flaw affects UPnP against by the new patch.
First is the buffer overflow handling components in the provision of e-mail advertisements UPnP-enabled devices on the network.
Second weakness from the Universal Plug and Play the failure to limit measures, the service will be taken to obtain information from a newly discovered device, making the system vulnerable to denial-of-service of the two.
Microsoft pointed out that the standard firewall, such as blocking port from 1900 to 5000, will protect corporate networks from Internet-based attacks. The company also said that the Internet Connection Firewall by default in Windows XP operating makes it harder to attack the use of the method.
This is the 59th security bulletin, Microsoft issued in 2001. Microsoft credited eEye Digital Security on this issue.
Latest Industry News: - Microsoft
- Free Tool Hunts Bots
- Found
- RPI, Law School Team to Offer Degrees in Tech Business Law
- Adobe's 2Q Profit Surges 24 Percent
- Duke: iPhone Not To Blame
- Cisco Closes the Books on Still Another Acquisition
- Microsoft Deal Values Facebook at $15B
- Netcraft
- Intel Unveils Low-Power Chip for 2-Way Blades
- Cisco Introduces New CallManager Security Features
- Special Report: Meta happens!
- You Move Me
- OS X Upgrade, IPhone May Boost Mac Sales
- CoSort 9 Eases Large XML/LDIF Conversion, Manipulation, Protection
- Appearance of Exploit Code Means Time Is Running Out to Apply Critical Windows Patch
- Vista Still Getting Mixed Reviews
- ISM’s PerfMan Grants IT Control over E-commerce Systems
- Making Amends
- Just What You Needed
3Com Adobe APC Apple BEA BICSI CheckPoint Cisco Citrix CIW CompTIA Computer Associates CWNP Dell ECcouncil EMC Enterasys Exam Express EXIN Extreme Networks File Maker Fortinet Foundry Fujitsu Guidance Software HDI HITACHI Hewlett Packard Huawei Hyperion IBM IISFA Intel ISACA ISC ISEB ISM Juniper Legato Lotus LPI McAfee McDATA Microsoft Mile2 Network Appliance Network General Nokia Nortel Novell OMG Oracle PMI Polycom Red Hat SAIR SAS Institute SCP SeeBeyond SNIA Sniffer Sun Sybase Symantec Teradata TIA TIBCO Trusecure Veritas VMware

MCSD .NET70-229 70-300 70-306 70-310 70-315 70-316 70-320 $269 Details |
MCAD .NET70-305 70-306 70-310 70-315 70-316 70-320 $229 Details |
LPI 2117-201 117-202 $79 Details |
CCVP642-642 642-432 642-426 642-444 642-453 $199 Details |
MCDBA70-228 70-229 70-290 70-293 $159 Details |
MCPD70-526 70-528 70-536 70-547 70-548 70-549 70-551 $269 Details |
MCTS70-235 70-526 70-528 70-529 70-536 70-551 70-552 70-553 $309 Details |
MCP70-270 70-290 $79 Details |
MBS CCDP MCD HTI+ Solaris 9 SCSA SCEA Solaris 10 SCSA SCA A+ CRM MCED MCSE 2003 Messaging SCMAD MCDST SSBB CCSP SCDME CCNP 9i IAD SCBCD CA MCSD .NET MCAD .NET LPI 2 CCVP MCDBA MCPD MCTS MCP SA MCSA 2003 CCI MPC MCITP CCDA SCSSSE SCJP 8i DBA CCNA MCA SC MCSE 2003 Security LPI 1 10g OCA SCWCD SCSI 9i DBA 10g DBA MCSE
920-182 000-062 920-440 000-914 MB6-509 920-110 9L0-506 1Y0-972 3M0-250 HP0-045 HP0-W03 642-452 70-301 250-101 HP0-P10 MB3-412 MB6-502 000-425 000-918 HP0-841 920-133 310-100 EE0-501 000-732 E20-820 920-231 HP0-791 DP-021W 646-471 HD0-300 9A0-802 1Z0-033 70-236 MB3-461 70-226 HP0-093 XK0-001 HP0-429 HP0-795 HP0-335 50-676 920-162 HP0-755 MK0-201 HP0-064 HP0-E01 920-166 NS0-121 70-234 190-831 920-131 3H0-002 642-901 920-164 MOS-AXP 70-121 CISSP 9L0-508 642-071 70-633

