affix.sourceforge.netConfirmation
http://affix.sourceforge.net/patch_hci_3_2_0 CVE-2005-1294
Linux Kernel 2.4.x/2.6.x - 'Bluez' BlueTooth Signed Buffer Index Privilege Escalation (2)
Record summary
CVE-2005-1294 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLinux Kernel 2.4.x/2.6.x - 'Bluez' BlueTooth Signed Buffer Index Privilege Escalation (2)ExploitDB exploitby qobaiashiNot analyzed1 file
References
420050424 DMA[2005-0423a] - 'Nokia Affix Bluetooth Integer Underflow'mailing list
http://marc.info/?l=bugtraq&m=111445064725591&w=2 digitalmunition.com
http://www.digitalmunition.com/DMA%5B2005-0423a%5D.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1294