CVE-2005-3995
sobexsrv < 1.0.0_pre3 - Remote Code Execution via Format String in OBEX File Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3995. PoCs published by Kevin Finisterre.
AI-analyzed exploit summary This exploit targets a Bluetooth sobexsrv remote syslog() vulnerability (CVE-2005-3995) by leveraging a format string attack to overwrite memory addresses and execute shellcode. It crafts a malicious input to trigger arbitrary code execution via the 'ussp-push' command.
Description
Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is enabled, allows remote attackers to execute arbitrary code via format string specifiers in file name arguments to OBEX commands.
Exploits (1)
This exploit targets a Bluetooth sobexsrv remote syslog() vulnerability (CVE-2005-3995) by leveraging a format string attack to overwrite memory addresses and execute shellcode. It crafts a malicious input to trigger arbitrary code execution via the 'ussp-push' command.