Mageia alert MGASA-2020-0419 (bluez)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2020-0419: Updated bluez packages fix a security vulnerability | |
Date: | Fri, 13 Nov 2020 22:21:45 +0100 | |
Message-ID: | <20201113212145.165289F6EB@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2020-0419 - Updated bluez packages fix a security vulnerability Publication date: 13 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0419.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-27153 Description: In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event. (CVE-2020-27153) References: - https://bugs.mageia.org/show_bug.cgi?id=27486 - https://www.debian.org/lts/security/2020/dla-2410 - https://lists.suse.com/pipermail/sle-security-updates/202... - https://lists.opensuse.org/opensuse-security-announce/202... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2... SRPMS: - 7/core/bluez-5.54-1.1.mga7