NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Symantec Exposes Windows Vista

Via Teredo

By Marius Oiaga, Technology News Editor

4th of April 2007, 11:13 GMT

Adjust text size:



Enlarge picture
Cupertino-based security company Symantec has taken another swing at Windows Vista designe to bring into focus Microsoft's inaccurate Teredo documentation and other common vulnerabilities
and exposures in the operating system. At the basis of Symantec's initiative are no less than nine new CVEs issued just last week under the CVE project. Symantec claims that all the CVEs have been requested by a third-party but that they are all based on its Windows Vista Network Attack Surface Analysis report published on March 7, 2007.

"We don't feel that most of the issues are especially significant. Microsoft reviewed the paper prior to its public release and Symantec would participate in any warranted responsible disclosure for vulnerabilities," stated Jim Hoagland, with the Symantec Security response.

Adopting a mild tone of voice, Hoagland revealed that just CVE-2007-1535 can be considered an important issue and even make it as a half decent vulnerability Symantec has focused intensively on, the new network protocol stack in Windows Vista claiming that the technology is immature and inherently vulnerable. "Teredo is an IPv6 transition technology that provides address assignment and host-to-host automatic tunneling for unicast IPv6 traffic when IPv6/IPv4 hosts are located behind one or multiple IPv4 network address translators (NATs)," according to a Microsoft description.

And CVE-2007-1535 focuses directly on Teredo. According to Symantec, the technology has a tendency to become active despite Microsoft's own documentation. "The described issue is that Teredo (an IPv4 to IPv6 transition technology that works through NATs) becomes qualified (active) even in situations where the Microsoft documentation says it should not be," Hoagland revealed.

According to Microsoft, the Teredo component is enabled in Windows Vista but also inactive by default. Symantec disputes this and revealed that Teredo automatically became active in several common scenarios.

TAGS:

Windows Vista | Teredo
Read by 1,140 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.2/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


When Windows .ani Files Attack

Attackers Can Potentially Run Malicious Applications on Windows Vista

Windows Vista, 90-Day Vulnerability Report

A Windows Vista Zero-Day Is Pure Gold

Windows Vista Is Hard As a Rock

Windows Vista Wide Open to StickyKeys Backdoor

Windows Vista - to Do or Not to Do, Security?

Microsoft Knew About the Critical .ANI Vista Vulnerability Since December 2006

Windows Vulnerabilities, Just as Severe in Vista

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM