CVE Vulnerabilities

CVE-2006-0212

Published: Jan 14, 2006 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by .. sequences in the RFILE argument of ussp-push.

Affected Software

Name Vendor Start Version End Version
Bluetooth_stack Toshiba * 4.00.23t (including)
Bluetooth_stack Toshiba 3.00.11 (including) 3.00.11 (including)
Bluetooth_stack Toshiba 3.00.12 (including) 3.00.12 (including)
Bluetooth_stack Toshiba 3.00.31a (including) 3.00.31a (including)
Bluetooth_stack Toshiba 3.00.32 (including) 3.00.32 (including)
Bluetooth_stack Toshiba 3.01.03 (including) 3.01.03 (including)
Bluetooth_stack Toshiba 3.10.00 (including) 3.10.00 (including)
Bluetooth_stack Toshiba 3.20.00 (including) 3.20.00 (including)
Bluetooth_stack Toshiba 3.20.01 (including) 3.20.01 (including)
Bluetooth_stack Toshiba 3.20.02 (including) 3.20.02 (including)
Bluetooth_stack Toshiba 3.20.04 (including) 3.20.04 (including)
Bluetooth_stack Toshiba 4.00.01t (including) 4.00.01t (including)
Bluetooth_stack Toshiba 4.00.11 (including) 4.00.11 (including)

References