|
Brought to you by:
Suppliers of:
|
|
|
| |
| "The Garmin Communicator Plugin lets you connect your Garmin GPS with your favorite website. Once the plugin is installed, just connect your Garmin GPS device to your computer, and you're on your way. The Garmin Communicator can send and retrieve data from any supported website." Secunia Research has discovered a vulnerability in Garmin Communicator Plug-In, which can be exploited by malicious people to bypass certain security restrictions. |
| |
Credit:
The information has been provided by Dyon Balding.
The original article can be found at: http://secunia.com/secunia_research/2009-16/
|
| |
Vulnerable Systems:
* Garmin Communicator Plug-In (npGarmin.dll) version 2.6.4.0
The vulnerability is caused due to a synchronisation error in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control (npGarmin.dll). This can be exploited to bypass the domain locking and dialog box presented to the user asking for confirmation that the untrusted site may access private data.
Successful exploitation allows full access (such as deleting data, retrieving personal information, or installing firmware updates) to any Garmin GPS products connected to the user's system.
Solution:
Set the kill-bit for the affected ActiveX control.
CVE Information:
CVE-2009-0194
|
|
|
|
|