Headline
CVE-2022-39177: USN-5481-1: BlueZ vulnerabilities | Ubuntu security notices | Ubuntu
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
Packages
- bluez - Bluetooth tools and daemons
Details
It was discovered that BlueZ incorrectly validated certain capabilities
and lengths when handling the A2DP profile. A remote attacker could use
this issue to cause BlueZ to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Canonical is offering Extended Security Maintenance
Canonical is offering Ubuntu Extended Security Maintenance (ESM) for security fixes and essential packages.
Find out more about ESM ›
Further reading
- Loading…
Related news
Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adversary with WMS group admin access could potentially exploit this vulnerability, leading to temporary denial-of-service.