LWN.net Logo

bluez: command execution

Package(s):bluez-utils CVE #(s):CAN-2005-2547
Created:August 17, 2005 Updated:August 26, 2005
Description: The bluez-utils package (through version 2.19) fails to properly validate device names. As a result, pairing the system with a device containing a maliciously-crafted name could result in the execution of arbitrary commands as root.
Alerts:
Mandriva MDKSA-2005:150 2005-08-25
Debian DSA-782-1 2005-08-23
Gentoo 200508-09 2005-08-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds