Vaisha Bernard discovered that blueman did not properly sanitize input on the
D-Bus interface to blueman-mechanism. A local attacker could possibly use this
issue to escalate privileges and run arbitrary code or cause a denial of
service (CVE-2020-15238).
- https://bugs.mageia.org/show_bug.cgi?id=27485
- https://ubuntu.com/security/notices/USN-4605-1
- https://www.cve.org/CVERecord?id=CVE-2020-15238
- 7/core/blueman-2.1.4-1.mga7
Get the latest Linux and open source security news straight to your inbox.