CVE-2005-2277: Critical severity Nokia Affix vulnerability
Published Jul 15, 2005
·Updated
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
Affected Software
2 affected components
Nokia Affix=3.2.0
Nokia Affix=2.1.2
Event History
Jul 15, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2277?
CVE-2005-2277 is considered to be of medium severity due to the ability for remote attackers to execute arbitrary commands.
2
How do I fix CVE-2005-2277?
To fix CVE-2005-2277, users should apply the security patches available for affected versions of Nokia Affix.
3
Which versions of Nokia Affix are affected by CVE-2005-2277?
CVE-2005-2277 affects Nokia Affix versions 2.1.2 and 3.2.0.
4
What type of attack does CVE-2005-2277 enable?
CVE-2005-2277 allows remote attackers to execute arbitrary commands through crafted filename arguments.
5
Is Bluetooth FTP client in Nokia Affix still vulnerable if updated?
Updating Nokia Affix to the patched versions should mitigate the vulnerability associated with CVE-2005-2277.