ALT-PU-2016-2219-1
Closed vulnerabilities
Modified: 2025-04-12
CVE-2016-9797
In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://www.securityfocus.com/bid/94652
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://www.securityfocus.com/bid/94652
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
Modified: 2025-04-12
CVE-2016-9798
In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00071.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00072.html
- http://www.securityfocus.com/bid/94652
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00071.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00072.html
- http://www.securityfocus.com/bid/94652
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
Modified: 2025-04-12
CVE-2016-9799
In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
Modified: 2025-04-12
CVE-2016-9800
In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The issue exists because "pin" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "pin_code_reply_cp *cp" parameter.
Modified: 2025-04-12
CVE-2016-9801
In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file.
Modified: 2025-04-12
CVE-2016-9802
In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://www.securityfocus.com/bid/94652
- https://www.spinics.net/lists/linux-bluetooth/msg68898.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://www.securityfocus.com/bid/94652
- https://www.spinics.net/lists/linux-bluetooth/msg68898.html
Modified: 2025-04-12
CVE-2016-9803
In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed.
Modified: 2025-04-12
CVE-2016-9804
In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "frm->ptr" parameter. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
Modified: 2025-04-12
CVE-2016-9917
In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://www.securityfocus.com/bid/95013
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html
- http://www.securityfocus.com/bid/95013
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
Modified: 2025-04-12
CVE-2016-9918
In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00054.html
- http://www.securityfocus.com/bid/95013
- https://www.spinics.net/lists/linux-bluetooth/msg68898.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00054.html
- http://www.securityfocus.com/bid/95013
- https://www.spinics.net/lists/linux-bluetooth/msg68898.html