7.5
CVE-2005-2547
- EPSS 2.4%
- Veröffentlicht 12.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:15:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bluez Project ≫ Bluez Version2.18
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.4% | 0.819 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://cvs.sourceforge.net/viewcvs.py/bluez/utils/hcid/security.c?r1=1.31&r2=1.34
http://secunia.com/advisories/16453
http://secunia.com/advisories/16476
http://sourceforge.net/mailarchive/forum.php?thread_id=7893206&forum_id=1881
http://www.debian.org/security/2005/dsa-782
http://www.gentoo.org/security/en/glsa/glsa-200508-09.xml
http://www.securityfocus.com/bid/14572
https://bugs.gentoo.org/show_bug.cgi?id=101557