>> Linux Kernel Bluetooth CAPI "cmtp_recv_interopmsg()" Memory Corruption Vulnerability
Title : Linux Kernel Bluetooth CAPI "cmtp_recv_interopmsg()" Memory Corruption Vulnerability VUPEN ID : VUPEN/ADV-2006-5037 CVE ID : CVE-2006-6106
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-17
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by remote attackers to take complete control of an affected system or cause a denial of service. This flaw is due to buffer overflow errors in the "cmtp_recv_interopmsg()" [net/bluetooth/cmtp/capi.c] function when handling malformed CAPI packets, which could be exploited by attackers to overwrite internal CMTP and CAPI data structures and execute arbitrary commands with elevated privileges.