BlueZ Arbitrary Command Execution Vulnerability
BID:14572
Info
BlueZ Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 14572 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2547 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Henryk Plötz is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 BlueZ BlueZ 2.15 BlueZ BlueZ 2.11 BlueZ BlueZ 1.24 |
| Not Vulnerable: |
BlueZ BlueZ 2.19 |
Discussion
BlueZ Arbitrary Command Execution Vulnerability
BlueZ is affected by an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this vulnerability will permit an attacker to execute arbitrary commands on the system hosting the affected application in the security context of the application. This may aid in further attacks against the underlying system; other attacks are also possible.
BlueZ is affected by an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this vulnerability will permit an attacker to execute arbitrary commands on the system hosting the affected application in the security context of the application. This may aid in further attacks against the underlying system; other attacks are also possible.
Exploit / POC
BlueZ Arbitrary Command Execution Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
BlueZ Arbitrary Command Execution Vulnerability
Solution:
Gentoo Linux has released security advisory GLSA 200508-09 addressing this issue. Gentoo recommends all bluez-utils users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=net-wireless/bluez-utils-2.19"
Debian GNU/Linux has released advisory DSA 782-1, along with fixes to address this issue. Please see the referenced advisory for further information.
Mandriva has released advisory MDKSA-2005:150 and fixes to address this issue. Please see the referenced advisory for links to fixes.
Conectiva has released security advisory CLSA-2005:1001 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
The vendor has addressed this issue in version 2.19:
BlueZ BlueZ 1.24
BlueZ BlueZ 2.11
BlueZ BlueZ 2.15
Solution:
Gentoo Linux has released security advisory GLSA 200508-09 addressing this issue. Gentoo recommends all bluez-utils users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=net-wireless/bluez-utils-2.19"
Debian GNU/Linux has released advisory DSA 782-1, along with fixes to address this issue. Please see the referenced advisory for further information.
Mandriva has released advisory MDKSA-2005:150 and fixes to address this issue. Please see the referenced advisory for links to fixes.
Conectiva has released security advisory CLSA-2005:1001 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
The vendor has addressed this issue in version 2.19:
BlueZ BlueZ 1.24
-
BlueZ bluez-libs-2.19.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-libs-2.19.tar.gz -
BlueZ bluez-utils-2.19.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-2.19.tar.gz
BlueZ BlueZ 2.11
-
Conectiva bluez-utils-2.11-71173U10_4cl.i386.rpm
Conectiva 10.0
ftp://atualizacoes.conectiva.com.br/10/RPMS/bluez-utils-2.11-71173U10_ 4cl.i386.rpm -
Conectiva bluez-utils-2.11-71173U10_4cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/bluez-utils-2.11-71173U10_ 4cl.i386.rpm
BlueZ BlueZ 2.15
-
Debian bluez-bcm203x_2.15-1.1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_alpha.deb -
Debian bluez-bcm203x_2.15-1.1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_amd64.deb -
Debian bluez-bcm203x_2.15-1.1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_arm.deb -
Debian bluez-bcm203x_2.15-1.1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_hppa.deb -
Debian bluez-bcm203x_2.15-1.1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_i386.deb -
Debian bluez-bcm203x_2.15-1.1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_ia64.deb -
Debian bluez-bcm203x_2.15-1.1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_m68k.deb -
Debian bluez-bcm203x_2.15-1.1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_mips.deb -
Debian bluez-bcm203x_2.15-1.1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_mipsel.deb -
Debian bluez-bcm203x_2.15-1.1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_powerpc.deb -
Debian bluez-bcm203x_2.15-1.1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_s390.deb -
Debian bluez-bcm203x_2.15-1.1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_sparc.deb -
Debian bluez-cups_2.15-1.1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_alpha.deb -
Debian bluez-cups_2.15-1.1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_amd64.deb -
Debian bluez-cups_2.15-1.1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_arm.deb -
Debian bluez-cups_2.15-1.1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_hppa.deb -
Debian bluez-cups_2.15-1.1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_i386.deb -
Debian bluez-cups_2.15-1.1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_ia64.deb -
Debian bluez-cups_2.15-1.1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_m68k.deb -
Debian bluez-cups_2.15-1.1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_mips.deb -
Debian bluez-cups_2.15-1.1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_mipsel.deb -
Debian bluez-cups_2.15-1.1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_powerpc.deb -
Debian bluez-cups_2.15-1.1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_s390.deb -
Debian bluez-cups_2.15-1.1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-cups_ 2.15-1.1_sparc.deb -
Debian bluez-pcmcia-support_2.15-1.1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_alpha.deb -
Debian bluez-pcmcia-support_2.15-1.1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_arm.deb -
Debian bluez-pcmcia-support_2.15-1.1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_hppa.deb -
Debian bluez-pcmcia-support_2.15-1.1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_i386.deb -
Debian bluez-pcmcia-support_2.15-1.1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_ia64.deb -
Debian bluez-pcmcia-support_2.15-1.1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_m68k.deb -
Debian bluez-pcmcia-support_2.15-1.1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_mips.deb -
Debian bluez-pcmcia-support_2.15-1.1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_mipsel.deb -
Debian bluez-pcmcia-support_2.15-1.1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_powerpc.deb -
Debian bluez-pcmcia-support_2.15-1.1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-pcmci a-support_2.15-1.1_sparc.deb -
Debian bluez-utils_2.15-1.1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_alpha.deb -
Debian bluez-utils_2.15-1.1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_amd64.deb -
Debian bluez-utils_2.15-1.1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_arm.deb -
Debian bluez-utils_2.15-1.1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_hppa.deb -
Debian bluez-utils_2.15-1.1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_i386.deb -
Debian bluez-utils_2.15-1.1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_ia64.deb -
Debian bluez-utils_2.15-1.1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_m68k.deb -
Debian bluez-utils_2.15-1.1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_mips.deb -
Debian bluez-utils_2.15-1.1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_mipsel.deb -
Debian bluez-utils_2.15-1.1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/contrib/b/bluez-utils/bluez-bc m203x_2.15-1.1_s390.deb -
Debian bluez-utils_2.15-1.1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_powerpc.deb -
Debian bluez-utils_2.15-1.1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_s390.deb -
Debian bluez-utils_2.15-1.1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bluez-utils/bluez-utils _2.15-1.1_sparc.deb
References
BlueZ Arbitrary Command Execution Vulnerability
References:
References:
- BlueZ Homepage (BlueZ)
- Project: BlueZ: Mailing Lists (BlueZ)