VYPR

rpm package

suse/bluez&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP2

pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2

Vulnerabilities (2)

  • CVE-2020-27153HigOct 15, 2020
    affected < 5.48-13.3.1fixed 5.48-13.3.1

    In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

  • CVE-2020-0556Mar 12, 2020
    affected < 5.48-13.3.1fixed 5.48-13.3.1

    Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access