« April 2006 | Main | August 2006 »

June 30, 2006

TOSHIBA Security Update

I have just been informed by Toshiba that there is a new security update (PC Bluetooth Stack Service Pack 2) that also installs on non-Toshiba PCs.
It is available for download at http://aps.toshiba-tro.de/bluetooth/.

Posted by Martin Herfurt at 05:14 PM

June 21, 2006

Update: TOSHIBA Advisory

I have just been informed that TOSHIBA published a stable version of the stack. You find it here for download:
aps.toshiba-tro.de/bluetooth
Go for the latest Version (4.00.36) and your problems should be solved.
Special Thanks to Toshiba for letting me know about this.

Posted by Martin Herfurt at 05:43 PM

Del(l)icate Issue

Earlier this year, members of the trifinite.group discovered an issue with the Toshiba Windows Bluetooth Stack. Strangers can remotely cause a system exception on Windows hosts when they know the address of the internal Bluetooth device of this machine by sending large l2cap echo requests to it (see BlueSmack attack).
Toshiba has been informed about this issue in the middle of February 2006 already but didn't manage to fix the problem. Since Toshiba has been informed once more in April 2006 and the issue still is within the product, we finally decided to publish an advisory addressing the problem so that users of the product are warned and can take countermeasures.

Posted by Martin Herfurt at 08:15 AM | Comments (0)