Out-of-bounds read in BlueZ - CVE-2016-9803
Published: December 2, 2019
Vulnerability identifier: #VU23114
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9803
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to a boundary condition within the le_meta_ev_dump() function in tools/parser/hci.c. A local user can pass a specially crafted dump file, trigger a buffer overflow and crash application.
Affected software
BlueZ
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
bluez
bluez-debuginfo
bluez-debugsource
libbluetooth3
libbluetooth3-debuginfo
bluez-cups
bluez-cups-debuginfo
bluez-devel
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
bluez
bluez-debuginfo
bluez-debugsource
libbluetooth3
libbluetooth3-debuginfo
bluez-cups
bluez-cups-debuginfo
bluez-devel
How to mitigate CVE-2016-9803
Install updates from vendor's website.
BlueZ - update to 5.43
bluez - update to 5.13-5.31.1
bluez-debuginfo - update to 5.13-5.31.1
bluez-debugsource - update to 5.13-5.31.1
libbluetooth3 - update to 5.13-5.31.1
libbluetooth3-debuginfo - update to 5.13-5.31.1
bluez-cups - update to 5.13-5.31.1
bluez-cups-debuginfo - update to 5.13-5.31.1
bluez-devel - update to 5.13-5.31.1
bluez - update to 5.13-5.31.1
bluez-debuginfo - update to 5.13-5.31.1
bluez-debugsource - update to 5.13-5.31.1
libbluetooth3 - update to 5.13-5.31.1
libbluetooth3-debuginfo - update to 5.13-5.31.1
bluez-cups - update to 5.13-5.31.1
bluez-cups-debuginfo - update to 5.13-5.31.1
bluez-devel - update to 5.13-5.31.1