CVE-2016-9801
Published: 03 December 2016
In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file.
Priority
CVSS 3 base score: 5.3
Status
Package | Release | Status |
---|---|---|
bluez Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Deferred
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Deferred
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Deferred
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Deferred
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was deferred [2020-01-06])
|
Notes
Author | Note |
---|---|
mdeslaur | as of 2020-02-07, appears unfixed crash in hcidump command line tool only |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9801
- https://www.spinics.net/lists/linux-bluetooth/msg68892.html
- NVD
- Launchpad
- Debian