HTC OBEX FTP Service Directory Traversal Vulnerability
BID:33359
Info
HTC OBEX FTP Service Directory Traversal Vulnerability
| Bugtraq ID: | 33359 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0244 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2009 12:00AM |
| Updated: | Jul 28 2011 11:50AM |
| Credit: | Alberto Moreno Tablado |
| Vulnerable: |
HTC Touch Viva 0 HTC TOUCH PRO 2 HTC TOUCH PRO 0 HTC TOUCH HD 0 HTC TOUCH FIND 0 HTC TOUCH DUAL 0 HTC TOUCH DIAMOND 0 HTC TOUCH CRUISE 0 HTC TOUCH 0 HTC S740 0 HTC S730 0 HTC S710 0 HTC P6500 0 HTC ADVANTAGE X7510 0 |
| Not Vulnerable: | |
Discussion
HTC OBEX FTP Service Directory Traversal Vulnerability
The HTC OBEX FTP service is prone to a directory-traversal vulnerability.
Exploiting this issue allows an attacker to write arbitrary files to locations outside the application's current directory, download arbitrary files, and obtain sensitive information. Other attacks may also be possible.
The issue affects HTC devices running the OBEX FTP service on Windows Mobile 6.0 and 6.1.
The HTC OBEX FTP service is prone to a directory-traversal vulnerability.
Exploiting this issue allows an attacker to write arbitrary files to locations outside the application's current directory, download arbitrary files, and obtain sensitive information. Other attacks may also be possible.
The issue affects HTC devices running the OBEX FTP service on Windows Mobile 6.0 and 6.1.
Exploit / POC
HTC OBEX FTP Service Directory Traversal Vulnerability
An attacker can exploit this issue by using an FTP client installed on a computer or device that has Bluetooth capabilities.
An attacker can exploit this issue by using an FTP client installed on a computer or device that has Bluetooth capabilities.
Solution / Fix
HTC OBEX FTP Service Directory Traversal Vulnerability
Solution:
Fixes are available. Please see the references for details.
Solution:
Fixes are available. Please see the references for details.
References
HTC OBEX FTP Service Directory Traversal Vulnerability
References:
References:
- HTC / Windows Mobile OBEX FTP Service Directory Traversal Vulnerability (Alberto Moreno Tablado)
- HTC / Windows Mobile OBEX FTP Service Directory Traversal ([email protected])
- Microsoft Bluetooth Stack OBEX Directory Traversal ([email protected] )
- Hotfix to enhance the security mechanism of Bluetooth FTP service for HTC Touch (HTC)