Description: Kevin Finisterre has reported a vulnerability in Affix, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an input validation error in the "event_pin_code_request()" function. This can be exploited to inject arbitrary shell commands on a vulnerable btsrv server via a specially crafted Bluetooth device name through a wireless Bluetooth connection.
The vulnerability has been reported in versions 2.1.2 and 3.2.0. Prior versions may also be affected.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.