Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15710

Опубликовано: 19 нояб. 2020
Источник: nvd
CVSS3: 5.3
CVSS3: 6.1
CVSS2: 3.6
EPSS Низкий

Описание

Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu1:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu2:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.1:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.2:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.3:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.4:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.5:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.6:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.7:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.8:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.9:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.10:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.11:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu3.12:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio_project:pulseaudio:1\:8.0-0ubuntu4:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS3

6.1 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-415
CWE-415

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.

CVSS3: 5.3
debian
около 5 лет назад

Potential double free in Bluez 5 module of PulseAudio could allow a lo ...

github
больше 3 лет назад

Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS3

6.1 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-415
CWE-415