bluez-5.44-7.el7

エラータID: AXSA:2020-565:03

Release date: 
Monday, October 5, 2020 - 10:30
Subject: 
bluez-5.44-7.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (Red Hat), and pcmcia configuration files.

Security Fix(es):

bluez: Improper access control in subsystem could result in privilege escalation and DoS (CVE-2020-0556)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 7 Release Notes linked from the References section.

CVE-2020-0556
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. bluez-5.44-7.el7.src.rpm
    MD5: dded04ebb8f00bd11fa038a0de53f59d
    SHA-256: 3b4799e0a0f9f8a84d2a0719e9e9bc43c28854c1e1ee5cbb906d10b76a048afd
    Size: 1.63 MB

Asianux Server 7 for x86_64
  1. bluez-5.44-7.el7.x86_64.rpm
    MD5: 700bba3fb88e3f78cc479e51ddf2c013
    SHA-256: 93ab48f3100208d9cb1197459c2526f4f547dd7b7a4f1e05e8d997a8d82761a4
    Size: 1.23 MB
  2. bluez-libs-5.44-7.el7.x86_64.rpm
    MD5: af6248247f802f398c15535cda22d0d9
    SHA-256: 9728d53c5ce47d05242d412c472ee4eaedb3905b6785189478a30c6cc1ec49d9
    Size: 79.64 kB
  3. bluez-libs-5.44-7.el7.i686.rpm
    MD5: ff8f6d634e11a167e7380b0436b0ff0c
    SHA-256: 8cde37ffce7a2148c7af8a80308c7e5618c1fa56b9251987d03107465f62aafa
    Size: 79.07 kB