Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22145
HistoryJul 09, 2009 - 12:00 a.m.

Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues

2009-07-0900:00:00
vulners.com
10

>> Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues

Title : Nokia Phones RealPlayer and MMS Viewer Memory Corruption Issues
VUPEN ID : VUPEN/ADV-2009-1815
CVE ID : GENERIC-MAP-NOMATCH
CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2009-07-08

Technical Description Receive VUPEN Security alerts in a Text format Receive VUPEN Security alerts in a PDF format Receive VUPEN Security alerts in an XML format

Multiple vulnerabilities have been identified in various Nokia phones, which could be exploited by remote attackers to crash an affected application or compromise a vulnerable device. These issues are caused by memory corruption errors in the "rarender.dll", "STH264HWDecHwDevice.dll", "clntcore.dll", "HxMmfCtrl.dll", "mdfh264payloadformat.dll", "MMFDevSound.dll", and "ArmRV89Codec.dll" librairies when processing malformed media files embedded in MMS, which could be exploited to crash an affected application or potentially execute arbitrary code.

Affected Products

Nokia E61i
Nokia E71
Nokia N96

Solution

VUPEN Security is not aware of any vendor-supplied patch.

References

http://www.vupen.com/english/advisories/2009/1815
https://www.sec-consult.com/files/Pwning_Nokia_V1.03_PUB.pdf

Credits

Vulnerabilities reported by Bernhard Mueller (SEC Consult Vulnerability Lab).

ChangeLog

2009-07-08 : Initial release