Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55310
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLSA-2005:1001
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory CLSA-2005:1001.

This missing update fixes weak input validation in
security.c for BlueZ's hcid that could allow remote
attackers to execute arbitrary commands via shell
metacharacters in the Bluetooth device name when
invoking the PIN helper.

Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001001
http://www.bluez.org/

Risk factor : High

CVSS Score:
7.5

Cross-Ref: BugTraq ID: 14572
Common Vulnerability Exposure (CVE) ID: CVE-2005-2547
http://www.securityfocus.com/bid/14572
Debian Security Information: DSA-782 (Google Search)
http://www.debian.org/security/2005/dsa-782
http://www.gentoo.org/security/en/glsa/glsa-200508-09.xml
http://sourceforge.net/mailarchive/forum.php?thread_id=7893206&forum_id=1881
http://secunia.com/advisories/16453
http://secunia.com/advisories/16476
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.