VYPR

rpm package

suse/bluez&distro=SUSE Linux Enterprise Module for Basesystem 15 SP1

pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1

Vulnerabilities (6)

  • CVE-2020-27153HigOct 15, 2020
    affected < 5.48-5.28.1fixed 5.48-5.28.1

    In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

  • CVE-2020-0556Mar 12, 2020
    affected < 5.48-5.25.1fixed 5.48-5.25.1

    Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access

  • CVE-2016-9917HigDec 8, 2016
    affected < 5.48-5.16.1fixed 5.48-5.16.1

    In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

  • CVE-2016-9802MedDec 3, 2016
    affected < 5.48-5.16.1fixed 5.48-5.16.1

    In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

  • CVE-2016-9798MedDec 3, 2016
    affected < 5.48-5.16.1fixed 5.48-5.16.1

    In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

  • CVE-2016-9797MedDec 3, 2016
    affected < 5.48-5.16.1fixed 5.48-5.16.1

    In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.