Handspring Visor Network HotSync Vulnerability
BID:920
Info
Handspring Visor Network HotSync Vulnerability
| Bugtraq ID: | 920 |
| Class: | Access Validation Error |
| CVE: |
CVE-2000-0058 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Posted to Bugtraq by Jay C Austad <[email protected]> on January 5, 1999. |
| Vulnerable: |
Handspring Visor Network HotSync 1.0 |
| Not Vulnerable: | |
Discussion
Handspring Visor Network HotSync Vulnerability
The Handspring Visor is a Palm-compatible personal organizer. It ships with Network Hotsync, an application designed to perform backups and synchronizations of the Visor to a PC or Macintosh computer over an IP network. There is no authentication done for this transaction, so anybody with a Visor users name and IP address can initiate the hotsync and retrieve the users email and other information. This also gives an attacker with a Visor the aability to send email as the user.
The Handspring Visor is a Palm-compatible personal organizer. It ships with Network Hotsync, an application designed to perform backups and synchronizations of the Visor to a PC or Macintosh computer over an IP network. There is no authentication done for this transaction, so anybody with a Visor users name and IP address can initiate the hotsync and retrieve the users email and other information. This also gives an attacker with a Visor the aability to send email as the user.
Exploit / POC
Handspring Visor Network HotSync Vulnerability
see discussion
see discussion
Solution / Fix
Handspring Visor Network HotSync Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].