An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for bluez ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3247-1 Rating: important References: #1194704 Cross-References: CVE-2022-0204 CVSS scores: CVE-2022-0204 (NVD) : 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-0204 (SUSE): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Workstation Extension 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bluez fixes the following issues: - CVE-2022-0204: Fixed check if the prepare writes would append more than the allowed maximum attribute length (bsc#1194704). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3247=1 - SUSE Linux Enterprise Workstation Extension 15-SP4: zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2022-3247=1 - SUSE Linux Enterprise Module for Desktop Applications15-SP4: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2022-3247=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-3247=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): bluez-5.62-150400.4.5.1 bluez-cups-5.62-150400.4.5.1 bluez-cups-debuginfo-5.62-150400.4.5.1 bluez-debuginfo-5.62-150400.4.5.1 bluez-debugsource-5.62-150400.4.5.1 bluez-deprecated-5.62-150400.4.5.1 bluez-deprecated-debuginfo-5.62-150400.4.5.1 bluez-devel-5.62-150400.4.5.1 bluez-test-5.62-150400.4.5.1 bluez-test-debuginfo-5.62-150400.4.5.1 libbluetooth3-5.62-150400.4.5.1 libbluetooth3-debuginfo-5.62-150400.4.5.1 - openSUSE Leap 15.4 (noarch): bluez-auto-enable-devices-5.62-150400.4.5.1 - openSUSE Leap 15.4 (x86_64): bluez-devel-32bit-5.62-150400.4.5.1 libbluetooth3-32bit-5.62-150400.4.5.1 libbluetooth3-32bit-debuginfo-5.62-150400.4.5.1 - SUSE Linux Enterprise Workstation Extension 15-SP4 (x86_64): bluez-cups-5.62-150400.4.5.1 bluez-cups-debuginfo-5.62-150400.4.5.1 bluez-debuginfo-5.62-150400.4.5.1 bluez-debugsource-5.62-150400.4.5.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (aarch64 ppc64le s390x x86_64): bluez-debuginfo-5.62-150400.4.5.1 bluez-debugsource-5.62-150400.4.5.1 bluez-devel-5.62-150400.4.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): bluez-5.62-150400.4.5.1 bluez-debuginfo-5.62-150400.4.5.1 bluez-debugsource-5.62-150400.4.5.1 bluez-deprecated-5.62-150400.4.5.1 bluez-deprecated-debuginfo-5.62-150400.4.5.1 libbluetooth3-5.62-150400.4.5.1 libbluetooth3-debuginfo-5.62-150400.4.5.1 References: https://www.suse.com/security/cve/CVE-2022-0204.html https://bugzilla.suse.com/1194704 . SUSE Security Advisory: Significant bluez patch resolves seriousvulnerability linked to CVE-2022-0204. Review for complete information!. SUSE Security Update, Bluez Patch, CVE-2022-0204, Linux Patch Management. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for bluez ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1198-1 Rating: moderate References: #1015173 Cross-References: CVE-2016-9918 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bluez fixes the following issues: Security issue fixed: - CVE-2016-9918: Fixed a out-of-bound read in the packet_hexdump function (bsc#1015173) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1198=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): bluez-5.48-lp150.4.10.1 bluez-cups-5.48-lp150.4.10.1 bluez-cups-debuginfo-5.48-lp150.4.10.1 bluez-debuginfo-5.48-lp150.4.10.1 bluez-debugsource-5.48-lp150.4.10.1 bluez-devel-5.48-lp150.4.10.1 bluez-test-5.48-lp150.4.10.1 bluez-test-debuginfo-5.48-lp150.4.10.1 libbluetooth3-5.48-lp150.4.10.1 libbluetooth3-debuginfo-5.48-lp150.4.10.1 - openSUSE Leap 15.0 (noarch): bluez-auto-enable-devices-5.48-lp150.4.10.1 - openSUSE Leap 15.0 (x86_64): bluez-devel-32bit-5.48-lp150.4.10.1 libbluetooth3-32bit-5.48-lp150.4.10.1 libbluetooth3-32bit-debuginfo-5.48-lp150.4.10.1 References: https://www.suse.com/security/cve/CVE-2016-9918.html https://bugzilla.suse.com/1015173 -- . To tackle the moderate severity concern, apply the latest openSUSE Security Update for bluez by updating your packagerepository, retrieving the latest version, and securing vulnerabilities. openSUSE Update, bluez Security Fix, moderate Threat. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.