Bug 74519 (CVE-2005-0750)

Summary: VUL-0: CVE-2005-0750: kernel: local root exploit in AF_BLUETOOTH
Product: [Novell Products] SUSE Security Incidents Reporter: Marcus Meissner <meissner>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Critical    
Priority: P5 - None CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: All   
Whiteboard: CVE-2005-0750: CVSS v2 Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: rs-2.6.tgz
rs.tar.gz
bluetooth.patch
bluetooth-24.patch

Description Marcus Meissner 2005-03-25 10:20:52 UTC
there is a local root exploit in AF_BLUETOOTH   
caused by a missing <0 check in  
net/bluetooth/af_bluetooth.c::bt_sock_create().  
  
(everyone can do   
  
socket(AF_BLUETOOTH,-xxxx,0); is the problem I think.  
  
)
Comment 1 Marcus Meissner 2005-03-25 10:26:15 UTC
CAN-2005-0750 
Comment 2 Marcus Meissner 2005-03-25 10:30:10 UTC
reported by ilja <ilja@suresec.org 
Comment 3 Marcus Meissner 2005-03-29 08:21:06 UTC
Created attachment 32818 [details]
rs-2.6.tgz
Comment 4 Marcus Meissner 2005-03-29 08:21:29 UTC
Created attachment 32819 [details]
rs.tar.gz
Comment 5 Marcus Meissner 2005-03-29 08:35:57 UTC
Created attachment 32820 [details]
bluetooth.patch

2.6 patch from Marcel
Comment 6 Marcus Meissner 2005-03-29 08:36:19 UTC
Created attachment 32821 [details]
bluetooth-24.patch

2.4 patch (by me)
Comment 7 Marcus Meissner 2005-03-29 08:48:41 UTC
swampid: 714 
Comment 8 Hubert Mantel 2005-03-29 09:41:19 UTC
Fix has been committed to all trees and kernels have been submitted for checkin
into autobuild.
Comment 9 Marcus Meissner 2005-04-05 13:35:06 UTC
urgent kernel updates + advisory has been released. 
 
patch is in all other branches for next update rounds too. 
 
-> fixed 
Comment 10 Thomas Biege 2009-10-13 21:13:45 UTC
CVE-2005-0750: CVSS v2 Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)