Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.704951
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-4951-1)
Summary:The remote host is missing an update for the Debian 'bluez' package(s) announced via the DSA-4951-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'bluez' package(s) announced via the DSA-4951-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in Bluez, the Linux Bluetooth protocol stack.

CVE-2020-26558

/ CVE-2021-0129

It was discovered that Bluez does not properly check permissions during pairing operation, which could allow an attacker to impersonate the initiating device.

CVE-2020-27153

Jay LV discovered a double free flaw in the disconnect_cb() routine in the gattool. A remote attacker can take advantage of this flaw during service discovery for denial of service, or potentially, execution of arbitrary code.

For the stable distribution (buster), these problems have been fixed in version 5.50-1.2~
deb10u2.

We recommend that you upgrade your bluez packages.

For the detailed security status of bluez please refer to its security tracker page at: [link moved to references]

Affected Software/OS:
'bluez' package(s) on Debian 10.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-26558
Debian Security Information: DSA-4951 (Google Search)
https://www.debian.org/security/2021/dsa-4951
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/
https://security.gentoo.org/glsa/202209-16
https://kb.cert.org/vuls/id/799380
https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/
https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
https://lists.debian.org/debian-lts-announce/2021/06/msg00022.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-27153
https://security.gentoo.org/glsa/202011-01
https://bugzilla.redhat.com/show_bug.cgi?id=1884817
https://github.com/bluez/bluez/commit/1cd644db8c23a2f530ddb93cebed7dacc5f5721a
https://github.com/bluez/bluez/commit/5a180f2ec9edfacafd95e5fed20d36fe8e077f07
https://lists.debian.org/debian-lts-announce/2020/10/msg00022.html
SuSE Security Announcement: openSUSE-SU-2020:1876 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00034.html
SuSE Security Announcement: openSUSE-SU-2020:1880 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00036.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-0129
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00517.html
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.