CVE-2006-6899: Medium severity Bluez Project Bluez vulnerability
Published Dec 31, 2006
·Updated
hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.
Affected Software
1 affected component
Bluez Project Bluez<=2.24
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Jan 9, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6899?
CVE-2006-6899 is considered to have a moderate severity level as it allows remote attackers to control Human Interface Devices.
2
How do I fix CVE-2006-6899?
To fix CVE-2006-6899, update BlueZ to version 2.25 or later, which addresses this vulnerability.
3
What are the potential impacts of CVE-2006-6899?
The potential impacts of CVE-2006-6899 include unauthorized control of connected mouse and keyboard devices.
4
Which versions of BlueZ are affected by CVE-2006-6899?
BlueZ versions up to and including 2.24 are affected by CVE-2006-6899.
5
Who can exploit CVE-2006-6899?
CVE-2006-6899 can be exploited by remote attackers with the capability to send crafted Bluetooth connections.