CVE-2005-2547

N/A Unknown
Published: August 12, 2005 Modified: April 16, 2026
View on NVD

Description

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://bugs.gentoo.org/show_bug.cgi?id=101557
Source: cve@mitre.org
Patch Vendor Advisory
http://secunia.com/advisories/16453
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/16476
Source: af854a3a-2127-422b-91ae-364da2661108
http://sourceforge.net/mailarchive/forum.php?thread_id=7893206&forum_id=1881
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.debian.org/security/2005/dsa-782
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200508-09.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/14572
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugs.gentoo.org/show_bug.cgi?id=101557
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.1%
78th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

bluez_project