PT-2005-3179 · Nokia · Nokia Affix

Kevin Finisterre

·

Published

2005-07-13

·

Updated

2008-09-05

·

CVE-2005-2250

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Nokia Affix versions 2.1.2 through 3.2.0
Description: The issue is related to a buffer overflow in the Bluetooth FTP client, specifically in the BTFTP component of Nokia Affix. This buffer overflow can be triggered by a remote attacker sending a long filename in an OBEX file share, potentially allowing the execution of arbitrary code.
Recommendations: For versions 2.1.2 through 3.2.0, consider disabling the BTFTP client until a patch is available to prevent potential exploitation. Restrict access to OBEX file shares to minimize the risk of arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2250
DSA-762-1

Affected Products

Nokia Affix