|
|||||||||||
|
SYMSA-2007-007: Palm OS Treo Smartphone Denial of Service
From: <research(at)symantec.com>
Date: Fri Aug 17 2007 - 09:21:57 EDT
Symantec Vulnerability Research
http://www.symantec.com/research
Security Advisory
Advisory ID: SYMSA-2007-007
Advisory Title: Palm OS Treo Smartphone Denial of Service
Authors: J.R. Wikes
Release Date: 20-08-2007
Application: N/A
Platforms: Palm Treo 650, 680, 700p & 755p Smartphones
Severity: Remotely exploitable / Denial of Service
Vendor status: Verified by vendor
CVE Number: CVE-2007-4213 [Requested]
Reference:
http://www.securityfocus.com/bid/25074Overview: Treo Smartphones running the Palm OS are vulnerable to a remote Denial of Service attack while connected to data networks allowing inbound ICMP traffic. It is possible for an attacker to launch this attack from the Internet by sending specially crafted ICMP requests at the targeted phone's assigned IP address. Details: Sending continuous ICMP echo requests with a packet size of 1470 bytes to the Smartphone's assigned IP address will invoke one (or more) of the following conditions on the device: latency, lockup, forced soft reset, or disconnection from the data network. It is also possible to achieve the same effects with a lower packet size by increasing the interval at which the echo requests are sent to the device Vendor Response: The Symantec issue outlined is an architectural limitation and we will continue monitoring it closely. However, we have not seen any cases where Palm products have been affected. Recommendation: In the interim of a fix being released by the Vendor to address this vulnerability, service providers should implement network filtering controls to restrict inbound ICMP requests to these devices. Common Vulnerabilities and Exposures (CVE) Information: The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems. CVE-2007-4213
For questions about this advisory, or to report an error: research@symantec.com For details on Symantec's Vulnerability Reporting Policy: http://www.symantec.com/research/Symantec-Responsible-Disclosure.pdf Symantec Vulnerability Research Advisory Archive: http://www.symantec.com/enterprise/research/archive.jsp Symantec Vulnerability Research GPG Key: http://www.symantec.com/research/Symantec_Vulnerability_Research_GPG.asc
To Report a Security Vulnerability in a Symantec Product: secure@symantec.com
For general information on Symantec's Product Vulnerability
reporting and response:
Symantec Product Advisory Archive:
Symantec Product Advisory PGP Key:
Copyright (c) 2007 by Symantec Corp.
Disclaimer
Symantec, Symantec products, and Symantec Consulting Services are
registered trademarks of Symantec Corp. and/or affiliated companies
in the United States and other countries. All other registered and
unregistered trademarks represented in this document are the sole
property of their respective companies/owners.
iD8DBQFGwIZ1uk7IIFI45IARAvmOAJ9i4zg62yxZcq3KJi+zn4KJ2/9QPgCdEl33
5invJfVK+rjARPomPUXHxAI=
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:12:46 EDT |
||||||||||
|
|||||||||||