SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

Motorola Milestone(Droid) Smartphone Remote Denial of Service


Arrow  WLB : WLB-2010020038  (About)
Arrow  SecurityAlert : None
Arrow  Date : 2010-02-08
Arrow  Credit          : David Vieira-Kurz
Arrow  Added by     : SecurityReason
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2010-02-08] Started

Arrow  Affected software :  Motorola Milestone(Droid)



Arrow  Text :  

[MajorSecurity Advisory #65]Motorola Milestone(Droid) Smartphone Remote
Denial of Service

Details
============
Product: Motorola Milestone(Droid) Smartphone
Security-Risk: low
Remote-Exploit: yes
Vendor-URL:
http://www.motorola.com/Consumers/US-EN/Consumer-Product-and-Services/Mobil
e-Phones/Motorola-DROID-US-EN?localeId=33
Vendor-Status: informed
Advisory-Status: published on 02-02-2010

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info

Affected Products:
============
Motorola Milestone(Droid) smartphone Browser with following useragent:
Mozilla/5.0 (Linux; U; Android 2.0; de-de; Milestone
Build/SHOLS_U2_01.03.1) AppleWebKit/530.17 (KHTML, like Gecko) Version/4.0
Mobile Safari/530.17

Original Advisory:
============
http://www.majorsecurity.info/index_2.php?adv=major_rls65

Introduction
============
The Motorola Milestone(droid) is a smartphone produced by Motorola based on
the android operation system.

More Details
============
A remotely exploitable vulnerability has been found in the JavaScript
Engine of the MobileSafari Browser(based on Webkit Engine) used on the
Motorola Milestone(droid) smartphone.
In detail, the following flaw was determined:
The Motorola Milestone(Droid) is prone to a denial of service vulnerability
when parsing certain HTML content. This is possible due to a failure in
handling exceptional conditions. This issue is caused by a memory
corruption error when handling javascript elements, which could be
exploited by remote attackers to crash the browser by tricking a user into
visiting a specially crafted web page. This issue can NOT be lead to remote
code execution, so that the potential security risk is rated low.

The exploit has been tested on a Motorola Milestone(Droid) using following
useragent:

Mozilla/5.0 (Linux; U; Android 2.0; de-de; Milestone
Build/SHOLS_U2_01.03.1) AppleWebKit/530.17 (KHTML, like Gecko) Version/4.0
Mobile Safari/530.17

Proof of Concept:
============
<script>
var overloadtag = "<marquee>";
for(x=1;x<=9999999999999;x++){
document.write(overloadtag);
}
&lt;/script&gt;

MajorSecurity
================
MajorSecurity is a German penetrationtesting and security research company
which focuses on web application security. We offer professional
penetrationtestings, security audits, source code reviews and reliable
proof of concepts. You will find more Information about MajorSecurity at
http://www.majorsecurity.info/

Unaltered electronic reproduction of this advisory is permitted. For all
other reproduction or publication, in printing or otherwise, contact
office@majorsecurity.info for permission.
Use of the advisory constitutes acceptance for use in an "as is"
condition. All warranties are excluded.
In no event shall majorsecurity and David Vieira-Kurz IT Security Services
be liable for any damages whatsoever including direct, indirect,
incidental, consequential, loss of business profits or special damages,
even if majorsecurity has been advised of the possibility of such damages.

Copyright 2010 MajorSecurity and David Vieira-Kurz IT Security Services.
All rights reserved. Terms of use apply.

--
--
David Vieira-Kurz IT Security Services
Tel: 0151 24 132 139
http://www.penetrationstest.net | http://www.sichereprogrammierung.de


If you want change this note, please use UCP


Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

Copyright © SecurityReason.com. All Rights Reserved.