CVE-2006-6908: Buffer Overflow

Published Dec 31, 2006
·
Updated

Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows CE on the HP IPAQ 2215 and 5450, allows remote attackers to cause a denial of service (service crash) and possibly execute arbitrary code via unspecified vectors.

Affected Software

7 affected components
Broadcom Widcomm Bluetooth=1.4.1.03
Broadcom Widcomm Bluetooth<=3
Broadcom Widcomm Bluetooth=1.3.2.7
Broadcom Widcomm Bluetooth=1.4.2.10
Microsoft Windows CE
Microsoft Windows Mobile
Microsoft Windows Embedded Compact

Event History

Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jan 9, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2006-6908?

CVE-2006-6908 has a high severity due to its potential for remote code execution through a buffer overflow.

2

What systems are affected by CVE-2006-6908?

CVE-2006-6908 affects several versions of the Widcomm Bluetooth stack, specifically versions 1.3.2.7, 1.4.1.03, and up to 3.x, along with Windows Mobile and Windows CE.

3

How do I fix CVE-2006-6908?

To mitigate CVE-2006-6908, users should upgrade to the latest version of the Widcomm Bluetooth software that addresses this vulnerability.

4

What kind of attack does CVE-2006-6908 enable?

CVE-2006-6908 allows an attacker to exploit a buffer overflow in the Bluetooth stack, potentially leading to arbitrary code execution.

5

Is CVE-2006-6908 a zero-day vulnerability?

CVE-2006-6908 is not a zero-day vulnerability as it was publicly disclosed and has known mitigation strategies.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203