#VU23108 Code Injection in BlueZ - CVE-2016-7837
Published: December 2, 2019
BlueZ
BlueZ Project
Description
The vulnerability allows an attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the parse_line() function used in some userland utilities. A remote attacker with physical proximity to the system can send a specially crafted data to the application and execute arbitrary code on the target system.