MGASA-2022-0235 - Updated bluez packages fix security vulnerability

Publication date: 18 Jun 2022
URL: https://advisories.mageia.org/MGASA-2022-0235.html
Type: security
Affected Mageia releases: 8

It was discovered that BlueZ incorrectly validated certain capabilities
and lengths when handling the A2DP profile. A remote attacker could use
this issue to cause BlueZ to crash, resulting in a denial of service, or
possibly execute arbitrary code.

References:
- https://bugs.mageia.org/show_bug.cgi?id=30556
- https://ubuntu.com/security/notices/USN-5481-1

SRPMS:
- 8/core/bluez-5.55-3.5.mga8

Mageia 2022-0235: bluez security update

It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile

Summary

It was discovered that BlueZ incorrectly validated certain capabilities and lengths when handling the A2DP profile. A remote attacker could use this issue to cause BlueZ to crash, resulting in a denial of service, or possibly execute arbitrary code.

References

- https://bugs.mageia.org/show_bug.cgi?id=30556

- https://ubuntu.com/security/notices/USN-5481-1

Resolution

MGASA-2022-0235 - Updated bluez packages fix security vulnerability

SRPMS

- 8/core/bluez-5.55-3.5.mga8

Severity
Publication date: 18 Jun 2022
URL: https://advisories.mageia.org/MGASA-2022-0235.html
Type: security

Related News