events.ccc.de
http://events.ccc.de/congress/2006-mediawiki//images/f/fb/23c3_Bluetooh_revisited.pdf CVE-2006-6899
BlueZ 1.x/2.x - HIDD Bluetooh HID Command Injection
Record summary
CVE-2006-6899 has a selected CVSS score of 5.4; EIP currently links 1 catalogued exploit.
Description
hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBlueZ 1.x/2.x - HIDD Bluetooh HID Command InjectionExploitDB exploitby Collin MullinerNot analyzed1 file
References
Showing 12 of 15mulliner.org
http://mulliner.org/bluetooth/hidattack.php 32830vdb entry
http://osvdb.org/32830 23747Third-party advisory
http://secunia.com/advisories/23747 23798Third-party advisory
http://secunia.com/advisories/23798 23879Third-party advisory
http://secunia.com/advisories/23879 25264Third-party advisory
http://secunia.com/advisories/25264 MDKSA-2007:014Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:014 RHSA-2007:0065Vendor advisory
http://www.redhat.com/support/errata/RHSA-2007-0065.html 20070104 23C3 - Bluetooth hacking revisted [Summary and Code]mailing list
http://www.securityfocus.com/archive/1/455889/100/0/threaded 22076vdb entry
http://www.securityfocus.com/bid/22076 USN-413-1Vendor advisory
http://www.ubuntu.com/usn/usn-413-1