BlueZ Arbitrary Command Execution Vulnerability Solution:
Gentoo Linux has released security advisory GLSA 200508-09 addressing this issue. Gentoo recommends all bluez-utils users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=net-wireless/bluez-utils-2.19"
Debian GNU/Linux has released advisory DSA 782-1, along with fixes to address this issue. Please see the referenced advisory for further information.
Mandriva has released advisory MDKSA-2005:150 and fixes to address this issue. Please see the referenced advisory for links to fixes.
Conectiva has released security advisory CLSA-2005:1001 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
The vendor has addressed this issue in version 2.19:
BlueZ BlueZ 1.24
BlueZ BlueZ 2.11
BlueZ BlueZ 2.15