Vulnerability in the Bluez Bluetooth stack

In the free Bluetooth stack BlueZ, which is used in Linux and Chrome OS distributions, identified vulnerability (CVE-2020-0556), potentially allowing an attacker to gain access to the system. Due to improper access checks in the implementation of the HID and HOGP Bluetooth profiles, the vulnerability , rather than taking focus. can enable denial of service or privilege escalation when connecting a malicious Bluetooth device without going through the device pairing procedure. A malicious Bluetooth device, without the pairing process, can impersonate another HID device (keyboard, mouse, game controllers, etc.) or organize a covert data injection into the input subsystem.

According to data For Intel, the issue appears in Bluez releases up to and including 5.52. It is unclear whether the issue affects release 5.53, which has not been announced publicly, but has been available since February through Git and in the build archive. Patches fixing the vulnerability were proposed on March 10, while the release1, 2was created on February 15. Updates in the distributions have not yet been formed ( 5.53 )Debian, Ubuntu, openSUSE, SUSE/openSUSE, ALT, Alpine).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster