|
|
|
|
| |
Credit:
The information has been provided by Kevin Finisterre..
The original article can be found at: http://www.securityfocus.com/bid/14230
|
| |
Vulnerable Systems:
* Nokia Affix 3.2
* Nokia Affix 3.1
* Nokia Affix 3.0
* Nokia Affix 2.1.2
* Nokia Affix 2.1.1
* Nokia Affix 2.1
* Nokia Affix 2.0.2
* Nokia Affix 2.0.1
* Nokia Affix 2.0
The Nokia Affix btftp client software is prone to a remote client-side buffer overflow vulnerability. The issue exists due to a lack of sufficient boundary checks that are performed on filename data before this data is copied into a finite memory buffer.
This issue may be exploited by an attacker that is under control of an OBEX File Transfer server, to execute arbitrary code in the context of the affected clients that connect to the malicious server, and request a directory listing.
Vendor Status:
Nokia had issued an update for this vulnerability .
CVE Information:
CVE-2005-2250
|
|
|
|
|