Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:1598

Опубликовано: 18 мая 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: bluez security update

The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (Rocky Enterprise Software Foundation), and pcmcia configuration files.

Security Fix(es):

  • bluez: double free in gatttool client disconnect callback handler in src/shared/att.c could lead to DoS or RCE (CVE-2020-27153)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
bluezx86_644.el8bluez-5.52-4.el8.x86_64.rpm
bluez-hid2hcix86_644.el8bluez-hid2hci-5.52-4.el8.x86_64.rpm
bluez-libsi6864.el8bluez-libs-5.52-4.el8.i686.rpm
bluez-libsx86_644.el8bluez-libs-5.52-4.el8.x86_64.rpm
bluez-obexdx86_644.el8bluez-obexd-5.52-4.el8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.8
redhat
больше 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.6
nvd
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.

CVSS3: 8.6
debian
около 5 лет назад

In BlueZ before 5.55, a double free was found in the gatttool disconne ...

suse-cvrf
около 5 лет назад

Security update for bluez