BlueZ Arbitrary Command Execution Vulnerability

BID:14572

Info

BlueZ Arbitrary Command Execution Vulnerability

Bugtraq ID: 14572
Class: Input Validation Error
CVE: CVE-2005-2547
Remote: Yes
Local: No
Published: Aug 16 2005 12:00AM
Updated: Jul 12 2009 05:06PM
Credit: Henryk Plötz is credited with the discovery of this vulnerability.
Vulnerable: Mandriva Linux Mandrake 10.2 x86_64
Mandriva Linux Mandrake 10.2
Mandriva Linux Mandrake 10.1 x86_64
Mandriva Linux Mandrake 10.1
Mandriva Linux Mandrake 10.0 AMD64
Mandriva Linux Mandrake 10.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Gentoo Linux
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
BlueZ BlueZ 2.15
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
BlueZ BlueZ 2.11
BlueZ BlueZ 1.24
Not Vulnerable: BlueZ BlueZ 2.19

Discussion

BlueZ Arbitrary Command Execution Vulnerability

BlueZ is affected by an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of this vulnerability will permit an attacker to execute arbitrary commands on the system hosting the affected application in the security context of the application. This may aid in further attacks against the underlying system; other attacks are also possible.

Exploit / POC

BlueZ Arbitrary Command Execution Vulnerability

No exploit is required.

Solution / Fix

BlueZ Arbitrary Command Execution Vulnerability

Solution:
Gentoo Linux has released security advisory GLSA 200508-09 addressing this issue. Gentoo recommends all bluez-utils users should upgrade to the latest version:

emerge --sync
emerge --ask --oneshot --verbose ">=net-wireless/bluez-utils-2.19"

Debian GNU/Linux has released advisory DSA 782-1, along with fixes to address this issue. Please see the referenced advisory for further information.

Mandriva has released advisory MDKSA-2005:150 and fixes to address this issue. Please see the referenced advisory for links to fixes.

Conectiva has released security advisory CLSA-2005:1001 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.

The vendor has addressed this issue in version 2.19:


BlueZ BlueZ 1.24

BlueZ BlueZ 2.11

BlueZ BlueZ 2.15

References

BlueZ Arbitrary Command Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report