[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4951-1 bluez -- bluez

ID: oval:org.secpod.oval:def:605595Date: (C)2021-08-09   (M)2024-02-19
Class: PATCHFamily: unix




Several vulnerabilities were discovered in Bluez, the Linux Bluetooth protocol stack. CVE-2020-26558 / CVE-2021-0129 It was discovered that Bluez does not properly check permissions during pairing operation, which could allow an attacker to impersonate the initiating device. CVE-2020-27153 Jay LV discovered a double free flaw in the disconnect_cb routine in the gattool. A remote attacker can take advantage of this flaw during service discovery for denial of service, or potentially, execution of arbitrary code.

Platform:
Debian 10.x
Product:
libbluetooth3
bluez
libbluetooth-dev
bluetooth
Reference:
DSA-4951-1
CVE-2020-26558
CVE-2020-27153
CVE-2021-0129
CVE    3
CVE-2020-27153
CVE-2021-0129
CVE-2020-26558

© SecPod Technologies