20060809 PocketPC MMS - Remote Code Injection/Execution Vulnerability and Denial-of-Servicemailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2006-August/048614.html CVE-2006-4132
PocketPC Mms Composer - 'WAPPush' Denial of Service
Record summary
CVE-2006-4132 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
ArcSoft MMS Composer 1.5.5.6 and possibly earlier, and 2.0.0.13 and possibly earlier, allow remote attackers to cause a denial of service (resource exhaustion and application crash) via WAPPush messages to UDP port UDP 2948.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPocketPC Mms Composer - 'WAPPush' Denial of ServiceExploitDB exploitby Collin MullinerNot analyzed1 file
References
1021426Third-party advisory
http://secunia.com/advisories/21426 1387Third-party advisory
http://securityreason.com/securityalert/1387 arcsoft.com
http://www.arcsoft.com/support/downloads/download_patches/mms.asp mulliner.org
http://www.mulliner.org/pocketpc/CollinMulliner_defcon14_pocketpcphones.pdf 20060810 PocketPC MMS - Remote Code Injection/Execution Vulnerability andDenial-of-Servicemailing list
http://www.securityfocus.com/archive/1/442841/100/0/threaded 19451vdb entry
http://www.securityfocus.com/bid/19451 mmscomposer-wappush-dos(28344)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/28344 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-4132 2156exploit
https://www.exploit-db.com/exploits/2156