security advisorydebianmoderate severity
It was reported that the BlueZ's HID profile implementation is not inline with the HID specification which mandates the use of Security Mode 4. The HID profile configuration option ClassicBondedOnly now defaults to "true" to make sure that input connections only come from . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5584-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso December 21, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : bluez CVE ID : CVE-2023-45866 Debian Bug : 1057914 It was reported that the BlueZ's HID profile implementation is not inline with the HID specification which mandates the use of Security Mode 4. The HID profile configuration option ClassicBondedOnly now defaults to "true" to make sure that input connections only come from bonded device connections. For the oldstable distribution (bullseye), this problem has been fixed in version 5.55-3.1+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 5.66-1+deb12u1. We recommend that you upgrade your bluez packages. For the detailed security status of bluez please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/bluez Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-5584-1 details a patch for BlueZ to meet HID compliance with enhanced security settings.. Debian Security, BlueZ Update, HID Compliance, Security Mode, Security Patch. . LinuxSecurity.com Team
Dec 21, 2023
Debian