Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27153

Опубликовано: 06 сент. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

Меры по смягчению последствий

This flaw can be mitigated by only connecting the gatttool client to trusted GATT servers/devices. The flaw is in the service discovery which occurs after a Bluetoth Low Energy (BLE) connection has been established to a device. A secondary mitigation for this flaw is to disable bluetooth. Instructions on disabling bluetooth in Red Hat Enterprise Linux are available at: https://access.redhat.com/solutions/2682931

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5bluez-gnomeOut of support scope
Red Hat Enterprise Linux 6bluezOut of support scope
Red Hat Enterprise Linux 7bluezOut of support scope
Red Hat Enterprise Linux 8bluezFixedRHSA-2021:159818.05.2021
Red Hat Enterprise Linux 8bluezFixedRHSA-2021:159818.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1884817bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE

EPSS

Процентиль: 83%
0.01899
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.6
nvd
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.6
debian
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconne ...

suse-cvrf
около 5 лет назад

Security update for bluez

suse-cvrf
около 5 лет назад

Security update for bluez

EPSS

Процентиль: 83%
0.01899
Низкий

8.8 High

CVSS3