iDefense Security Advisory 06.25.09 – Remote exploitation of a stack-based buffer overflow vulnerability in Motorola Inc.’s Timbuktu Pro could allow attackers to execute arbitrary code with SYSTEM privileges. Timbuktu fails to properly handle user-supplied data passed through a named pipe session. When the PlughNTCommand named pipe receives an overly large character string, a buffer overflow will occur resulting in arbitrary code execution. iDefense has confirmed the existence of this vulnerability in Timbuktu Pro version 8.6.5. Previous versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78669/06.25.09-2.txt
Source: https://packetstormsecurity.com/files/78669/iDEFENSE-Security-Advisory-2009-06-25.2.html

