vendor:
N/A
by:
kf_lists
9.3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Bluetooth sobexsrv remote syslog() exploit
This exploit is a remote code execution vulnerability in the Bluetooth sobexsrv service. It allows an attacker to execute arbitrary code on the target system by sending a specially crafted packet to the service. The exploit uses the exit() function to overwrite the return address of the stack frame with the address of the shellcode. The shellcode is then executed.
Mitigation:
The best way to mitigate this vulnerability is to disable the Bluetooth sobexsrv service.