Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-43400

Опубликовано: 04 нояб. 2021
Источник: debian
EPSS Низкий

Описание

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bluezfixed5.62-1package
bluezignoredstretchpackage

Примечания

  • Introduced by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=93b64d9ca8a2bb663e37904d4b2c702c58a36e4f (5.40)

  • Fixed by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=838c0dc7641e1c991c0f3027bf94bee4606012f8 (5.62)

EPSS

Процентиль: 39%
0.00172
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 4 лет назад

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS3: 9.1
redhat
больше 4 лет назад

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS3: 9.1
nvd
больше 4 лет назад

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS3: 9.1
github
больше 3 лет назад

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS3: 9.1
fstec
больше 4 лет назад

Уязвимость компонента database.c стека протоколов Bluetooth для ОС Linux BlueZ, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 39%
0.00172
Низкий