Motorola RAZR JPEG Processing Buffer Overflow

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
252.471
Località
Torino
Secunia Advisory: SA30409
Release Date: 2008-05-28

Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

OS: Motorola RAZR



Description:
A vulnerability has been reported in Motorola RAZR, which can be exploited by malicious people to compromise a vulnerable device.

The vulnerability is caused due to a boundary error in the JPEG thumbprint component. This can be exploited to cause a stack-based buffer overflow via a specially crafted JPEG image sent via MMS.

Successful exploitation allows execution of arbitrary code, but requires that the user accepts the malicious image.

Solution:
The vendor recommends updating to the latest firmware version. Please contact the vendor for more information.



Bollettino di Sicurezza
 
Indietro
Alto Basso