Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Symbian / Nokia N96 multiple security vulnerabilities

  Explit NSeries, ESeries

  SEC Consult SA-20090707-0 :: Symbian S60 / Nokia firmware media codecs multiple memory corruption vulnerabilities

  Pwning Nokia phones (and other Symbian based smartphones)

From:VUPEN
Date:09.07.2009
Subject:Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues

>> Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues

Title : Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues
VUPEN ID : VUPEN/ADV-2009-1815
CVE ID : GENERIC-MAP-NOMATCH
CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2009-07-08


Technical Description     Receive VUPEN Security alerts in a Text format   Receive VUPEN Security alerts in a PDF format   Receive VUPEN Security alerts in an XML format

Multiple vulnerabilities have been identified in various Nokia phones, which could be exploited by remote attackers to crash an affected application or compromise a vulnerable device. These issues are caused by memory corruption errors in the "rarender.dll", "STH264HWDecHwDevice.dll", "clntcore.dll", "HxMmfCtrl.dll", "mdfh264payloadformat.dll", "MMFDevSound.dll", and "ArmRV89Codec.dll" librairies when processing malformed media files embedded in MMS, which could be exploited to crash an affected application or potentially execute arbitrary code.

Affected Products

Nokia E61i
Nokia E71
Nokia N96

Solution

VUPEN Security is not aware of any vendor-supplied patch.

References

http://www.vupen.com/english/advisories/2009/1815
https://www.sec-consult.com/files/Pwning_Nokia_V1.03_PUB.pdf

Credits

Vulnerabilities reported by Bernhard Mueller (SEC Consult Vulnerability Lab).

ChangeLog

2009-07-08 : Initial release

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server