Motorola.Timbuktu.Pro.PlughNTCommand

NameMotorola.Timbuktu.Pro.PlughNTCommand.Buffer.Overflow
Last Updated DateDec 29, 2009
Release DateAug 27, 2009
SeverityCritical
ImpactSystem compromise
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in Motorola Timbuktu Pro.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted request sent to the PlughNTCommand named pipe. It allows a remote attacker to execute arbitrary code.
Affected ProductsMotorola Timbuktu Pro 8.6.5
Motorola Timbuktu Pro 8.6.3.1367
Recommended ActionsUpgrade to a non-vulnerable version:
http://www.netopia.com/software/products/tb2/win/upgrade_version_8.html
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1394
Reference/shttp://www.securityfocus.com/bid/35496 (BugTraq)
Reference: VID-17637