Feeds

Text message freezes Siemens 35 and 45 phones

Patch available

  • alert
  • submit to reddit

Designing a Defense for Mobile Applications

Users of Siemens 35 and 45 series phones have been warned of a bug which allows the handsets to be disabled by an incoming text message.

The fault is linked to the enhanced messaging service technology in the phones. A correctly formatted incoming message can freeze the 35 series phone immediately and cause the 45 series to hang for up to two minutes. To activate the flaw, the message would need to contain a single word from the phone's language menu, preceded by a special character and surrounded by quotes, such as "%English" or "%Deutsch."

The incoming message effectively instructs the handset to display an EMS symbol which doesn't exist in its library, freezing or stalling the handset, depending on the model. The bug is not thought to erase or corrupt information on the handsets, but may force users to turn the phone off and on again.

While Siemens has moved to downplay the bug, users complained that the flaw constitutes a genuine Denial of Service vulnerability. The 35 series is no longer in production; a software update for the 45 series from the Siemens Web site.

Siemens has been aware of the bug for some time but PC World reports that the company did not publicise the flaw in case attackers exploited it.

The Siemens flaw follows a glitch discovered last month in the Nokia 6210, which was also found to be susceptible to Denial of Service attacks. A vulnerability could let an attacker use the phone's VCard attachments facility to reboot or disable the handset.

Nokia said it did not intend release a patch for that vulnerability, as chances for its exploitation were considered remote. The Nokia flaw was discovered by US company @Stake, which said the bug illustrated the need for new mobile phone features to be thoroughly tested and debugged before introduction. © ENN

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Apple orders huge MOUNTAIN of 80 MILLION 'Air' iPhone 6s
Bigger, harder trouser bulges foretold for fanbois
Bring back error correction, say Danish 'net boffins
We don't need no steenkin' TCP/IP retransmission and the congestion it causes
GoTenna: How does this 'magic' work?
An ideal product if you believe the Earth is flat
Samsung Z Tizen OS mobe is post-phoned – this time for good?
Russian launch for Sammy's non-droid knocked back
Telstra to KILL 2G network by end of 2016
GSM now stands for Grave-Seeking-Mobile network
Seeking LTE expert to insert small cells into BT customers' places
Is this the first step to a FON-a-like 4G network?
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.