CVE-2006-1367
CVE-2006-1367
The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and view phonebook entries and saved SMS messages by connecting on Bluetooth channel 3 and tricking the user into pressing Grant, aka a "Blueline" attack. NOTE: while user-assisted, the attack is made more feasible because of a GUI misrepresentation issue that allows a default message to be replaced by an attacker-specified one.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/27454unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044287.htmlhttp://secunia.com/advisories/19319https://exchange.xforce.ibmcloud.com/vulnerabilities/25402http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txthttp://www.securityfocus.com/archive/1/428431/100/0/threadedhttp://www.securityfocus.com/bid/17190http://www.vupen.com/english/advisories/2006/1045