CVE-2022-0204

Description

A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.05

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2022:2883-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libbluetooth3-debuginfo-5.55-150300.3.11.1.x86_64.rpmLinux
SUSE-SU-2022:2883-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) bluez-deprecated-debuginfo-5.55-150300.3.11.1.x86_64.rpmLinux
Bluetooth tools and daemons (USN-5275-1) bluez_5.48-0ubuntu3.8_i386.debLinux
Bluetooth tools and daemons (USN-5275-1) bluez_5.48-0ubuntu3.8_amd64.debLinux
Bluetooth tools and daemons (USN-5275-1) bluez_5.53-0ubuntu3.5_i386.debLinux
Bluetooth tools and daemons (USN-5275-1) bluez_5.53-0ubuntu3.5_amd64.debLinux
Bluetooth tools and daemons (USN-5275-1) bluez_5.60-0ubuntu2.2_i386.debLinux
Bluetooth tools and daemons (USN-5275-1) bluez_5.60-0ubuntu2.2_amd64.debLinux
Bluetooth tools and daemons (USN-5275-1) libbluetooth3_5.48-0ubuntu3.8_i386.debLinux
Bluetooth tools and daemons (USN-5275-1) libbluetooth3_5.48-0ubuntu3.8_amd64.debLinux
Bluetooth tools and daemons (USN-5275-1) libbluetooth3_5.53-0ubuntu3.5_i386.debLinux
Bluetooth tools and daemons (USN-5275-1) libbluetooth3_5.53-0ubuntu3.5_amd64.debLinux
Bluetooth tools and daemons (USN-5275-1) libbluetooth3_5.60-0ubuntu2.2_i386.debLinux
Bluetooth tools and daemons (USN-5275-1) libbluetooth3_5.60-0ubuntu2.2_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234