Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
BlueZ could be made to crash or run programs as your login if it received
specially crafted Bluetooth requests.
Software Description:
- bluez: Bluetooth tools and daemons
Details:
Julian Rauchberger discovered that BlueZ did not correctly handle certain
memory operations. An attacker could possibly use this issue to leak
sensitive information or execute arbitrary code.
(CVE-2019-8921, CVE-2019-8922)
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS bluez 5.37-0ubuntu5.3+esm5 Available with Ubuntu Pro libbluetooth3 5.37-0ubuntu5.3+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-7265-1
CVE-2019-8921, CVE-2019-8922
Get the latest Linux and open source security news straight to your inbox.