Lucene search

K
cve[email protected]CVE-2008-1440
HistoryJun 12, 2008 - 2:32 a.m.

CVE-2008-1440

2008-06-1202:32:00
CWE-1284
web.nvd.nist.gov
30
cve-2008-1440
microsoft
windows xp
windows server 2003
pgm
denial of service

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.2

Confidence

High

EPSS

0.053

Percentile

93.1%

Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the β€œPGM Invalid Length Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_server_2003sp1
OR
microsoftwindows_server_2003Match-sp2
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp3
VendorProductVersionCPE
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp3::
microsoftwindows_server_2003-cpe:/o:microsoft:windows_server_2003:-:sp2::
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp2::
microsoftwindows_server_2003cpe:/o:microsoft:windows_server_2003::sp1::

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.2

Confidence

High

EPSS

0.053

Percentile

93.1%