CVE-2006-2366

NameCVE-2006-2366
Descriptionircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files via an arbitrary destination file name in an OBEX File Transfer session.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs366484

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libopenobex (PTS)buster, bullseye1.7.2-1fixed
bookworm1.7.2-2.1fixed
sid, trixie1.7.2-2.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libopenobexsource(unstable)1.2-3366484

Search for package or bug name: Reporting problems