<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ObiHai on System Overlord</title><link>https://systemoverlord.com/tags/obihai.html</link><description>Recent content in ObiHai on System Overlord</description><generator>Hugo</generator><language>en-us</language><managingEditor>david@systemoverlord.com (David Tomaschik)</managingEditor><webMaster>david@systemoverlord.com (David Tomaschik)</webMaster><lastBuildDate>Mon, 22 Aug 2016 00:00:00 +0000</lastBuildDate><atom:link href="https://systemoverlord.com/tags/obihai/index.xml" rel="self" type="application/rss+xml"/><item><title>ObiHai ObiPhone: Multiple Vulnerabilties</title><link>https://systemoverlord.com/2016/08/22/obihai-obiphone-multiple-vulnerabilties.html</link><pubDate>Mon, 22 Aug 2016 00:00:00 +0000</pubDate><author>david@systemoverlord.com (David Tomaschik)</author><guid>https://systemoverlord.com/2016/08/22/obihai-obiphone-multiple-vulnerabilties.html</guid><description>&lt;p&gt;&lt;strong&gt;Note that this a duplicate of the
&lt;a href="http://seclists.org/fulldisclosure/2016/Aug/111"&gt;advisory sent to the full-disclosure&lt;/a&gt;
mailing list.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;
&lt;p&gt;Multiple vulnerabilities were discovered in the web management interface of the ObiHai ObiPhone products. The Vulnerabilities were discovered during a black box security assessment and therefore the vulnerability list should not be considered exhaustive.&lt;/p&gt;
&lt;h2 id="affected-devices-and-versions"&gt;Affected Devices and Versions&lt;/h2&gt;
&lt;p&gt;ObiPhone 1032/1062 with firmware less than 5-0-0-3497.&lt;/p&gt;
&lt;h2 id="vulnerability-overview"&gt;Vulnerability Overview&lt;/h2&gt;
&lt;p&gt;Obi-1. Memory corruption leading to free() of an attacker-controlled address&lt;br&gt;
Obi-2. Command injection in WiFi Config&lt;br&gt;
Obi-3. Denial of Service due to buffer overflow&lt;br&gt;
Obi-4. Buffer overflow in internal socket handler&lt;br&gt;
Obi-5. Cross-site request forgery&lt;br&gt;
Obi-6. Failure to implement RFC 2617 correctly&lt;br&gt;
Obi-7. Invalid pointer dereference due to invalid header&lt;br&gt;
Obi-8. Null pointer dereference due to malicious URL&lt;br&gt;
Obi-9. Denial of service due to invalid content-length&lt;/p&gt;</description></item></channel></rss>