ircp_io.c in libopenobex for ircp 1.2, when ircp is run...
Low severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
May 15, 2006
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 31, 2023
ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files via an arbitrary destination file name in an OBEX File Transfer session.
References