Vulnerability Development mailing list archives

PalmOS crashes receiving SMS images using Handspring VisorPhone


From: Brian Wright <commorancy () yahoo com>
Date: Mon, 22 Oct 2001 14:20:15 -0700 (PDT)

Hello,

A friend and I were playing around sending SMS
messages the other day between a Nokia 3390 and his
Handspring VisorPhone/Visor Prism combo.  Sending text
messages seemed to work just fine.  However, on the
Nokia, there is an option of sending SMS images. 
Apparently, they are fairly large as they take a while
to send.  

The VisorPhone appears capable of accepting these
messages, but the VisorPhone database inside the
PalmOS isn't (at least, the version he had loaded). 
Whenever it transfers the image into the VisorPhone
database, it fatally crashes PalmOS and leaves the
VisorPhone database corrupted.  In order to recover,
he had to reboot the Visor (which disconnects the
call) and then attempt to delete the phone database
(which includes SMS messages).  This has the affect of
deleting all VisorPhone information (call logs, SMS
archived messages, custom messages, etc).  I doubt it
touched the standard PalmOS contacts database.

I tested it twice with the same results.  So, if
you're into crashing VisorPhones, try sending an SMS
image from a Nokia. :)  This vulnerability may also
exist when sending custom ringtones and other Nokia
specific SMS messages.

I don't know the exact version of the VisorPhone
software/hardware nor the exact version of PalmOS
running on the Visor Prism, but it's likely to work
with what's shipping today.  I also haven't tested on
anything other than the Visor as I don't have access,
but other PalmOS based phones may be vulnerable.


=====
--
Brian Wright <commorancy () yahoo com>

__________________________________________________
Do You Yahoo!?
Make a great connection at Yahoo! Personals.
http://personals.yahoo.com


Current thread: