Bug 24482

Summary: bluez new security issue CVE-2016-9918
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Shlomi Fish <shlomif>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: geiger.david68210, mhrambo3501
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: bluez-5.45-2.2.mga6.src.rpm CVE:
Status comment:

Description David Walser 2019-03-08 22:32:37 CET
SUSE has issued an advisory on February 28:
http://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html

I don't know if we've fixed this issue.
David Walser 2019-03-09 02:24:51 CET

Assignee: bugsquad => shlomif

Comment 1 David GEIGER 2019-03-28 06:52:59 CET
I looked at this security issue but I don't found any fixes for this one in current 5.45 release, seems it is fixed since 5.44 release.

CC: (none) => geiger.david68210

Comment 2 David Walser 2019-04-25 00:15:47 CEST
I'm not sure about that, it looks like SUSE had to patch 5.48 for this:
http://lists.suse.com/pipermail/sle-security-updates/2019-April/005283.html
Comment 3 Mike Rambo 2019-11-06 21:22:38 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
Status: NEW => RESOLVED
CC: (none) => mrambo

Comment 4 David Walser 2019-11-25 20:57:22 CET
I suspect CVE-2016-9797 CVE-2016-9798 CVE-2016-9802 CVE-2016-9917, fixed in:
https://lists.opensuse.org/opensuse-updates/2019-05/msg00171.html

are a similar situation.  Hopefully the fixes are already in 5.50.