BlueZ HIDD Bluetooh HID Command Injection Vulnerability
BID:22076
Info
BlueZ HIDD Bluetooh HID Command Injection Vulnerability
| Bugtraq ID: | 22076 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-6899 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2007 12:00AM |
| Updated: | May 14 2007 11:28PM |
| Credit: | Collin Mulliner is credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux Desktop version 4 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 BlueZ BlueZ 2.19 BlueZ BlueZ 2.15 BlueZ BlueZ 2.11 BlueZ BlueZ 1.24 BlueZ BlueZ 1.23 BlueZ BlueZ 1.17 BlueZ BlueZ 1.16 BlueZ BlueZ 1.12 BlueZ BlueZ 1.5 BlueZ BlueZ 2.20 |
| Not Vulnerable: |
BlueZ BlueZ 2.25 BlueZ BlueZ 3.8 |
Discussion
BlueZ HIDD Bluetooh HID Command Injection Vulnerability
BlueZ hidd is prone to a device-command-injection vulnerability.
A remote attacker can exploit this issue to gain control of mouse and keyboard HIDs (human interface device). This will allow the attacker to interact with the targeted computer in the context of the currently logged-in user.
Versions prior to 2.25 are vulnerable.
BlueZ hidd is prone to a device-command-injection vulnerability.
A remote attacker can exploit this issue to gain control of mouse and keyboard HIDs (human interface device). This will allow the attacker to interact with the targeted computer in the context of the currently logged-in user.
Versions prior to 2.25 are vulnerable.
Exploit / POC
BlueZ HIDD Bluetooh HID Command Injection Vulnerability
The following example exploit is available:
The following example exploit is available:
Solution / Fix
BlueZ HIDD Bluetooh HID Command Injection Vulnerability
Solution:
The vendor has addressed this issue as of version 2.25. Please see the references for more information.
BlueZ BlueZ 2.20
BlueZ BlueZ 1.12
BlueZ BlueZ 1.16
BlueZ BlueZ 1.17
BlueZ BlueZ 1.23
BlueZ BlueZ 1.24
BlueZ BlueZ 1.5
BlueZ BlueZ 2.11
BlueZ BlueZ 2.15
BlueZ BlueZ 2.19
Solution:
The vendor has addressed this issue as of version 2.25. Please see the references for more information.
BlueZ BlueZ 2.20
-
Ubuntu bluez-cups_2.20-0ubuntu3.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-cups_2 .20-0ubuntu3.1_amd64.deb -
Ubuntu bluez-cups_2.20-0ubuntu3.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-cups_2 .20-0ubuntu3.1_i386.deb -
Ubuntu bluez-cups_2.20-0ubuntu3.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-cups_2 .20-0ubuntu3.1_powerpc.deb -
Ubuntu bluez-cups_2.20-0ubuntu3.1_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-cups_2 .20-0ubuntu3.1_sparc.deb -
Ubuntu bluez-pcmcia-support_2.20-0ubuntu3.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-pcmcia -support_2.20-0ubuntu3.1_i386.deb -
Ubuntu bluez-pcmcia-support_2.20-0ubuntu3.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-pcmcia -support_2.20-0ubuntu3.1_powerpc.deb -
Ubuntu bluez-pcmcia-support_2.20-0ubuntu3.1_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-pcmcia -support_2.20-0ubuntu3.1_sparc.deb -
Ubuntu bluez-utils_2.20-0ubuntu3.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-utils_ 2.20-0ubuntu3.1_amd64.deb -
Ubuntu bluez-utils_2.20-0ubuntu3.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-utils_ 2.20-0ubuntu3.1_i386.deb -
Ubuntu bluez-utils_2.20-0ubuntu3.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-utils_ 2.20-0ubuntu3.1_powerpc.deb -
Ubuntu bluez-utils_2.20-0ubuntu3.1_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/b/bluez-utils/bluez-utils_ 2.20-0ubuntu3.1_sparc.deb
BlueZ BlueZ 1.12
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 1.16
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 1.17
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 1.23
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 1.24
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 1.5
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 2.11
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 2.15
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz
BlueZ BlueZ 2.19
-
BlueZ bluez-utils-3.8.tar.gz
http://www.bluez.org/redirect.php?url=http%3A%2F%2Fbluez.sf.net%2Fdown load%2Fbluez-utils-3.8.tar.gz -
Mandriva bluez-utils-2.19-7.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva bluez-utils-2.19-7.1.20060mdk.src.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva bluez-utils-2.19-7.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva bluez-utils-cups-2.19-7.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva bluez-utils-cups-2.19-7.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download
References
BlueZ HIDD Bluetooh HID Command Injection Vulnerability
References:
References:
- 23C3 - Bluetooth hacking revisted [Summary and Code] (Thierry Zoller)
- BlueZ Homepage (BlueZ)
- Red Hat Security Advisory RHSA-2007-0065: bluez-utils security update (Red Hat)