Описание
A double stack-based buffer overflow was found in the BlueZ AVRCP controller implementation. A nearby BR/EDR peripheral can send a crafted AVRCP player-settings response that supplies an attacker-controlled attribute count, causing avrcp_list_player_attributes_rsp() and avrcp_get_current_player_value() in profiles/audio/avrcp.c to write attacker-controlled data past fixed-size stack buffers, potentially leading to a crash or code execution in the bluetoothd daemon.
Отчет
Red Hat CVSSv3 score is an estimate from CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. This vulnerability requires user interaction and does not have any impact on the subsequent system, thus the scope is unchanged.
Меры по смягчению последствий
Affected version is v5.87 and fixed in commit b21c216d580cf303681bfe9eab60a5414d8b6cc0.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bluez | Affected | ||
| Red Hat Enterprise Linux 6 | bluez | Not affected | ||
| Red Hat Enterprise Linux 7 | bluez | Not affected | ||
| Red Hat Enterprise Linux 8 | bluez | Not affected | ||
| Red Hat Enterprise Linux 9 | bluez | Affected |
Показывать по
Дополнительная информация
Статус:
7.1 High
CVSS3
Связанные уязвимости
7.1 High
CVSS3