Sony Ericsson Multiple Phone Models WAP Push Remote Denial of Service Vulnerability
BID:33433
Info
Sony Ericsson Multiple Phone Models WAP Push Remote Denial of Service Vulnerability
| Bugtraq ID: | 33433 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2009 12:00AM |
| Updated: | Jan 27 2009 06:29PM |
| Credit: | Mobile Security Lab |
| Vulnerable: |
Sony Ericsson Z610i 0 Sony Ericsson W910i 0 Sony Ericsson W880i 0 Sony Ericsson W660i 0 Sony Ericsson K810i 0 Sony Ericsson K660i 0 Sony Ericsson K618i 0 Sony Ericsson K610i 0 Sony Ericsson K530i 0 |
| Not Vulnerable: | |
Discussion
Sony Ericsson Multiple Phone Models WAP Push Remote Denial of Service Vulnerability
Multiple Sony Ericsson phones are prone to a denial-of-service vulnerability because they fail to handle specially crafted WAP Push network traffic.
A remote attacker may exploit this issue to cause vulnerable devices to reboot or hang, resulting in a denial-of-service condition.
This issue affects the following phone models:
W910i
W660i
K618i
K610i
Z610i
K810i
K660i
W880i
K530i
Other devices may also be vulnerable.
Multiple Sony Ericsson phones are prone to a denial-of-service vulnerability because they fail to handle specially crafted WAP Push network traffic.
A remote attacker may exploit this issue to cause vulnerable devices to reboot or hang, resulting in a denial-of-service condition.
This issue affects the following phone models:
W910i
W660i
K618i
K610i
Z610i
K810i
K660i
W880i
K530i
Other devices may also be vulnerable.
Exploit / POC
Sony Ericsson Multiple Phone Models WAP Push Remote Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Sony Ericsson Multiple Phone Models WAP Push Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sony Ericsson Multiple Phone Models WAP Push Remote Denial of Service Vulnerability
References:
References:
- MSL-2008-001 SonyEricsson WAP Push Denial of Service (Mobile Security Lab)
- Sony Ericsson Mobile Communications (Sony)
- SonyEricsson WAP Push Denial of Service (Mobile Security Lab
)