SUSE-SU-2019:1339-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1339-1
SUSE-SU-2019:1339-1
Summary: Security update for bluez
Details: This update for bluez fixes the following issues: Security vulnerability addressed: - CVE-2016-9797: Fixed a buffer over-read in l2cap_dump() (bsc#1013708). - CVE-2016-9798: Fixed a use-after-free in conf_opt() (bsc#1013712). - CVE-2016-9917: Fixed a heap-based buffer overflow in read_n() (bsc#1015171). - CVE-2016-9802: Fixed a buffer over-read in l2cap_packet() (bsc#1013893). - CVE-2016-9918: Fixed an out-of-bounds stack read in packet_hexdump(), which could be triggered by processing a corrupted dump file and will result in a crash of the hcidump tool (bsc#1015173)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191339-1/, https://bugzilla.suse.com/1013708, https://bugzilla.suse.com/1013712, https://bugzilla.suse.com/1013893, https://bugzilla.suse.com/1015171, https://bugzilla.suse.com/1015173, https://www.suse.com/security/cve/CVE-2016-9797, https://www.suse.com/security/cve/CVE-2016-9798, https://www.suse.com/security/cve/CVE-2016-9802, https://www.suse.com/security/cve/CVE-2016-9917, https://www.suse.com/security/cve/CVE-2016-9918
Affected packages
Package
Name: bluez
Purl: pkg:rpm/suse/bluez&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
