Symantec Vulnerability Research
http://www.symantec.com/research
Security Advisory
Advisory ID: SYMSA-2007-012
Advisory Title: Microsoft Windows CE IGMP Denial of Service
Author: Ollie Whitehouse / ollie_whitehouse@symantec.com
Release Date: 22-10-2007
Application: Windows CE 5.01 / Windows Mobile 5
Platform: Microsoft Windows
Severity: Denial of Service
CVE Name: N/A
*Vulnerability Description*
SynCE is an open source project, whose objective is to provide a way of
communicating with a Windows CE or Pocket PC device, from a computer
running Linux, *BSD or other unices. For more information see
http://www.synce.org/
The vdccm daemon (part of the SynCE package) is vulnerable to a remote
command injection, which can be exploited by malicious remote attackers.