BugTraq
Denial Of Service in Internet Explorer for MS Windows Mobile 5.0 Feb 09 2007 11:55AM
clappymonkey gmail com (1 replies)
Re: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0 Feb 09 2007 06:08PM
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net) (1 replies)
RE: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0 Feb 09 2007 06:55PM
McCarty, Eric C. (emccarty er ucsd edu) (1 replies)
Re: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0 Feb 13 2007 07:12AM
Nicolas RUFF (nicolas ruff gmail com)
> 1). 90 days is plenty of time to fix a vulnerability, and in this case
> the author is merely stating the details of which will be revealed after
> 90 days. I doubt this will lead to any mass exploitation as I imagine
> you will need to go to a "specially crafted" website to exploit this DoS
> condition anyway. "... should the device browser access a WML page
> with malformed content..."

In the case of embedded devices, I think bugfix is not a matter of time.

Even if the hardware vendor is willing to build a new, bugfixed ROM for
a device that is outdated within 3 monthes of its release, nobody is
ever going to reflash his iPaq/SmartPhone/whatever, apart from a couple
of geeks who are willing to loose their data and reinstall all their
applications.

The hotfix is "buy a new one".

Regards,
- Nicolas RUFF

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus