WIDCOMM Bluetooth Communication Software Multiple Unspecified Buffer Overflow Vulnerabilities
BID:10914
Info
WIDCOMM Bluetooth Communication Software Multiple Unspecified Buffer Overflow Vulnerabilities
| Bugtraq ID: | 10914 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0775 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Mark Rowe and Matt Moore of Pentest Limited. |
| Vulnerable: |
WIDCOMM BTStackServer 1.4.2 .10 WIDCOMM BTStackServer 1.3.2 .7 WIDCOMM Bluetooth Communication Software 1.4.1 .03 |
| Not Vulnerable: |
WIDCOMM BTW WIDCOMM BT-CE/PPC 3.0 |
Discussion
WIDCOMM Bluetooth Communication Software Multiple Unspecified Buffer Overflow Vulnerabilities
WIDCOMM Bluetooth Communication Software is susceptible to multiple unspecified remote buffer overflow vulnerabilities. These vulnerabilities exist due to insufficient boundary checks performed by the application.
An unauthenticated remote attacker can trigger an overflow conditions by supplying malformed service requests.
Various devices from multiple vendors are thought to be affected by these issues, as they are implemented with WIDCOMM software. These issues have been verified by the researchers in BTStackServer version 1.3.2.7 and 1.4.2.10 running on Microsoft Windows XP and Windows 98. HP IPAQ 5450 running WinCE 3.0 with Bluetooth software version 1.4.1.03 is reported prone as well.
WIDCOMM Bluetooth Communication Software BTW & BT-CE/PPC 3.0 do not appear to be affected by these issues.
WIDCOMM Bluetooth Communication Software is susceptible to multiple unspecified remote buffer overflow vulnerabilities. These vulnerabilities exist due to insufficient boundary checks performed by the application.
An unauthenticated remote attacker can trigger an overflow conditions by supplying malformed service requests.
Various devices from multiple vendors are thought to be affected by these issues, as they are implemented with WIDCOMM software. These issues have been verified by the researchers in BTStackServer version 1.3.2.7 and 1.4.2.10 running on Microsoft Windows XP and Windows 98. HP IPAQ 5450 running WinCE 3.0 with Bluetooth software version 1.4.1.03 is reported prone as well.
WIDCOMM Bluetooth Communication Software BTW & BT-CE/PPC 3.0 do not appear to be affected by these issues.
Exploit / POC
WIDCOMM Bluetooth Communication Software Multiple Unspecified Buffer Overflow Vulnerabilities
The researchers responsible for discovering these issues have developed a proof of concept to trigger the vulnerabilities. This proof of concept is not available to the public at the moment.
KF <[email protected]> has created an exploit for one of these issues. A patch to alter ussp-push-0.4 is provided in the referenced email from KF, "have you ever been BluePIMped?".
The researchers responsible for discovering these issues have developed a proof of concept to trigger the vulnerabilities. This proof of concept is not available to the public at the moment.
KF <[email protected]> has created an exploit for one of these issues. A patch to alter ussp-push-0.4 is provided in the referenced email from KF, "have you ever been BluePIMped?".
Solution / Fix
WIDCOMM Bluetooth Communication Software Multiple Unspecified Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WIDCOMM Bluetooth Communication Software Multiple Unspecified Buffer Overflow Vulnerabilities
References:
References:
- have you ever been BluePIMped? ([email protected])
- Homepage (WIDCOMM)
- have you ever been BluePIMped? ("KF (lists)"
) - ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows (Pentest Security Advisories
)