漏洞信息详情
BlueZ 越边界读取漏洞
漏洞简介
BlueZ是一套官方的Linux蓝牙协议栈。
BlueZ 5.42中的monitor/packet.c源文件的‘packet_hexdump’函数存在越边界读取漏洞。攻击者可借助受损的dump文件利用该漏洞造成btmon崩溃。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,详情请关注厂商主页:
http://www.bluez.org/
参考网址
来源:BID
链接:http://www.securityfocus.com/bid/95013
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00054.html
来源:MISC
链接:https://www.spinics.net/lists/linux-bluetooth/msg68898.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191353-2.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191339-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191353-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190510-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190841-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1881/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76322
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1881.2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/78290
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Bluez-out-of-bounds-memory-reading-via-packet-hexdump-28926
受影响实体
- Bluez_project Bluez:5.42<!--2000-1-1-->
补丁
- BlueZ 越边界读取漏洞的修复措施<!--2016-12-9-->
还没有评论,来说两句吧...