>> Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues
Title : Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues
VUPEN ID : VUPEN/ADV-2009-1815
CVE ID : GENERIC-MAP-NOMATCH
CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2009-07-08
Technical Description Receive VUPEN Security alerts in a Text format Receive VUPEN Security alerts in a PDF format Receive VUPEN Security alerts in an XML format
Multiple vulnerabilities have been identified in various Nokia phones, which could be exploited by remote attackers to crash an affected application or compromise a vulnerable device. These issues are caused by memory corruption errors in the "rarender.dll", "STH264HWDecHwDevice.dll", "clntcore.dll", "HxMmfCtrl.dll", "mdfh264payloadformat.dll", "MMFDevSound.dll", and "ArmRV89Codec.dll" librairies when processing malformed media files embedded in MMS, which could be exploited to crash an affected application or potentially execute arbitrary code.
Affected Products
Nokia E61i
Nokia E71
Nokia N96
Solution
VUPEN Security is not aware of any vendor-supplied patch.
References
http://www.vupen.com/english/advisories/2009/1815
https://www.sec-consult.com/files/Pwning_Nokia_V1.03_PUB.pdf
Credits
Vulnerabilities reported by Bernhard Mueller (SEC Consult Vulnerability Lab).
ChangeLog
2009-07-08 : Initial release