LWN.net Logo

bluez: input validation flaw

Package(s):bluez-libs bluez-utils CVE #(s):CVE-2008-2374
Created:July 15, 2008 Updated:October 16, 2008
Description: From the Red Hat advisory: An input validation flaw was found in the Bluetooth Session Description Protocol (SDP) packet parser used by the Bluez Bluetooth utilities. A Bluetooth device with an already-established trust relationship, or a local user registering a service record via a UNIX® socket or D-Bus interface, could cause a crash, or possibly execute arbitrary code with privileges of the hcid daemon.
Alerts:
Red Hat RHSA-2008:0581-01 2008-07-14
CentOS CESA-2008:0581 2008-07-14
Mandriva MDVSA-2008:145 2007-07-14
Fedora FEDORA-2008-6133 2008-09-05
Fedora FEDORA-2008-6133 2008-09-05
SuSE SUSE-SR:2008:019 2008-09-26
Fedora FEDORA-2008-6140 2008-10-16

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds