Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27153

Опубликовано: 15 окт. 2020
Источник: nvd
CVSS3: 8.6
CVSS2: 7.5
EPSS Низкий

Описание

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:*
Версия до 5.55 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01899
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.8
redhat
больше 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.6
debian
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconne ...

suse-cvrf
около 5 лет назад

Security update for bluez

suse-cvrf
около 5 лет назад

Security update for bluez

EPSS

Процентиль: 83%
0.01899
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-415