Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2010-0240
StatusCandidate
DescriptionThe TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
SeverityHigh
CVSS score10
CVSS vector(AV:N/AC:L/Au:N/C:C/I:C/A:C)
PhaseAssigned (21.08.2010)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0240
ReferencesCERT : TA10-040A
 MS : MS10-009
 OVAL : oval:org.mitre.oval:def:8400
SecurityVulns:Microsoft Windows TCP/IP and TCP/IPv6 multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server