Windows MS-DOS Device Name DoS vulnerabilities

From: richardcaat_private
Date: Fri Jul 06 2001 - 15:43:41 PDT

  • Next message: Jair Pedro: "Re: [COVERT-2001-04] Vulnerability in Oracle 8i TNS Listener"

    Uhmm,
    
    I was thinking, some of the advisories published only talked about requesting 
    a device name. the ms site says two or more. the issue you name is only 
    win9x, yet some guy posted about a problem in NT today using ONE device 
    name.
    
    Win ME was also affeccted in some advisories. One would expect it to be 
    fixed in that edition of windows if this is indeed the same problem.
    
    Some advisories say the box would just lock up not give any blue screen.
    
    Am I missing something here?
    
    
    >AFFECTED SYSTEMS
    >
    >Microsoft Windows 95
    >Microsoft Windows 98
    >Microsoft Windows 98 SE
    >
    >CONCLUSION : patch your OS, and stop whining about so
    >called 'bugs' in applications, you will never be able
    >to completely patch the problem that way.
    >
    >PATCH
    >
    >Go to the Microsoft Knowledge Base @
    >http://search.support.microsoft.com/kb/c.asp
    >
    >And find the article with article ID Q256015
    >(titled Fatal Exception 0E with Multiple MS-DOS Device
    >Names in Path)
    
    Free, encrypted, secure Web-based email at www.hushmail.com
    



    This archive was generated by hypermail 2b30 : Sat Jul 07 2001 - 13:13:30 PDT