Out-of-bounds read in BlueZ - CVE-2016-9803

 

Out-of-bounds read in BlueZ - CVE-2016-9803

Published: December 2, 2019


Vulnerability identifier: #VU23114
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9803
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to a boundary condition within the le_meta_ev_dump() function in tools/parser/hci.c. A local user can pass a specially crafted dump file, trigger a buffer overflow and crash application.


Affected software

BlueZ
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
bluez
bluez-debuginfo
bluez-debugsource
libbluetooth3
libbluetooth3-debuginfo
bluez-cups
bluez-cups-debuginfo
bluez-devel

How to mitigate CVE-2016-9803

Install updates from vendor's website.

BlueZ - update to 5.43
bluez - update to 5.13-5.31.1
bluez-debuginfo - update to 5.13-5.31.1
bluez-debugsource - update to 5.13-5.31.1
libbluetooth3 - update to 5.13-5.31.1
libbluetooth3-debuginfo - update to 5.13-5.31.1
bluez-cups - update to 5.13-5.31.1
bluez-cups-debuginfo - update to 5.13-5.31.1
bluez-devel - update to 5.13-5.31.1

External References

Related Security Bulletins