=========================================================================Ubuntu Security Notice USN-4605-1
October 27, 2020

blueman vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Blueman could be made to run programs if it received specially crafted
input.

Software Description:
- blueman: Graphical bluetooth manager

Details:

Vaisha Bernard discovered that blueman did not properly sanitize input
on the d-bus interface to blueman-mechanism. A local attacker could
possibly use this issue to escalate privileges and run arbitrary code or
cause a denial of service. (CVE-2020-15238)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  blueman                         2.1.3-2ubuntu1

Ubuntu 20.04 LTS:
  blueman                         2.1.2-1ubuntu0.1

Ubuntu 18.04 LTS:
  blueman                         2.0.5-1ubuntu1.1

Ubuntu 16.04 LTS:
  blueman                         2.0.4-1ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4605-1
  CVE-2020-15238

Package Information:
  https://launchpad.net/ubuntu/+source/blueman/2.1.3-2ubuntu1
  https://launchpad.net/ubuntu/+source/blueman/2.1.2-1ubuntu0.1
  https://launchpad.net/ubuntu/+source/blueman/2.0.5-1ubuntu1.1
  https://launchpad.net/ubuntu/+source/blueman/2.0.4-1ubuntu2.1

Ubuntu 4605-1: Blueman vulnerability

October 27, 2020
Blueman could be made to run programs if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: blueman 2.1.3-2ubuntu1 Ubuntu 20.04 LTS: blueman 2.1.2-1ubuntu0.1 Ubuntu 18.04 LTS: blueman 2.0.5-1ubuntu1.1 Ubuntu 16.04 LTS: blueman 2.0.4-1ubuntu2.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4605-1

CVE-2020-15238

Severity
October 27, 2020

Package Information

https://launchpad.net/ubuntu/+source/blueman/2.1.3-2ubuntu1 https://launchpad.net/ubuntu/+source/blueman/2.1.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/blueman/2.0.5-1ubuntu1.1 https://launchpad.net/ubuntu/+source/blueman/2.0.4-1ubuntu2.1

Related News