Jeroen van Wolffelaar has reported a vulnerability in Open OBEX, which can be exploited by malicious people to manipulate certain data on a user's system.
The vulnerability is caused due to "ircp_io.c" failing to check for existing files with the same name before replacing them with files that are sent by another user. This can potentially be exploited to replace files in the user's current directory.
Successful exploitation requires that the user has accepted a file transfer from another user.
The vulnerability has been reported in version 1.2. Other versions may also be affected.
Solution: Do not accept file transfers from untrusted users.
Provided and/or discovered by: Jeroen van Wolffelaar
Original Advisory: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=366484
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to firstname.lastname@example.org