Bug 17361 - blueman new privilege escalation security issue CVE-2015-8612
Summary: blueman new privilege escalation security issue CVE-2015-8612
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/668770/
Whiteboard: MGA5-64-OK MGA5-32-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-12-18 23:48 CET by David Walser
Modified: 2015-12-28 20:24 CET (History)
2 users (show)

See Also:
Source RPM: blueman-2.0.2-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-12-18 23:48:09 CET
A CVE has been requested for a security issue fixed upstream in blueman:
http://openwall.com/lists/oss-security/2015/12/18/6

The upstream commit to fix the issue is linked in the message above.  Given the timestamp, it wouldn't have been included in the 2.0.2 release.  Mageia 5 is also likely affected.

Reproducible: 

Steps to Reproduce:
David Walser 2015-12-18 23:48:17 CET

Whiteboard: (none) => MGA5TOO

Comment 1 Atilla ÖNTAŞ 2015-12-19 00:09:23 CET
blueman-2.0.3-1.mga6 is submitted and should hit mirrors soon for Cauldron. Will update blueman ( which is still old git) for Mga5 to 2.0.3 stable version
Comment 2 David Walser 2015-12-19 00:11:30 CET
Thanks Atilla.

Version: Cauldron => 5
Whiteboard: MGA5TOO => (none)

Comment 3 Atilla ÖNTAŞ 2015-12-19 00:34:05 CET
I have uploaded a updated blueman package for Mageia 5.

Suggested advisory:
========================

Updated blueman-2.0.3-1.mga5 package fixes a a privilege escalation vulnerability which effects blueman in mga5.(mga#17361)

This update also provides a stable release of blueman instead of a old git snapshot.

References:
http://openwall.com/lists/oss-security/2015/12/18/6
https://github.com/blueman-project/blueman/issues/416
https://bugs.mageia.org/show_bug.cgi?id=17361
========================

Updated packages in core/updates_testing:
========================
blueman-2.0.3-1.mga5

Source RPMs: 
blueman-2.0.3-1.mga5.src.rpm
Atilla ÖNTAŞ 2015-12-19 00:34:31 CET

Assignee: tarakbumba => qa-bugs

Comment 4 David Walser 2015-12-19 03:54:37 CET
CVE-2015-8612:
http://openwall.com/lists/oss-security/2015/12/19/1

Suggested advisory:
========================

Updated blueman package fixes security vulnerability:

Privilege escalation vulnerability in blueman before 2.0.3 in the dbus API
(CVE-2015-8612).

References:
http://openwall.com/lists/oss-security/2015/12/19/1
https://github.com/blueman-project/blueman/issues/416

Summary: blueman new privilege escalation security issue => blueman new privilege escalation security issue CVE-2015-8612

Comment 5 David Walser 2015-12-21 21:43:17 CET
Debian has issued an advisory for this on December 18:
https://www.debian.org/security/2015/dsa-3427

URL: (none) => http://lwn.net/Vulnerabilities/668770/

Comment 6 Len Lawrence 2015-12-26 19:59:37 CET
mga5  x86_64  

Probably no PoC for this.

Before the update both blueman and bluedevil were installed.  I had never had much luck with blueman so have moved to bluedevil which was much more reliable.  To test the update I uninstalled bluedevil and removed the blueman applet.

Installed the update and ran the blueman-manager which placed the applet on the panel and allowed bluetooth to be enabled.  Added an audio device and connected to it immediately.  Switched off and tried again.  An immediate connection, so this is good for 64-bits.  Thanks for that Attila.

CC: (none) => tarazed25

Len Lawrence 2015-12-26 20:00:03 CET

Whiteboard: (none) => MGA5-64-OK

Comment 7 Len Lawrence 2015-12-26 22:38:13 CET
mga5  i586 vbox  KDE, Mate, LXDE, GNOME Classic

Neither blueman nor bluedevil were able to see the hardware adapter in virtualbox.  Is bluetooth supported in vbox?  virtualbox-guest-additions is installed.
Comment 8 David Walser 2015-12-26 22:48:33 CET
(In reply to Len Lawrence from comment #7)
> Is bluetooth supported in vbox?

I would be shocked if it was.
Comment 9 Len Lawrence 2015-12-26 23:10:51 CET
I had been wondering if it had anything to do with the USB adapter but it appears not so I shall take your word for it.

Have to leave the i586 test to somebody else unless I can resurrect my only piece of 32bit hardware which has been been about to drop into the bin.
Comment 10 Len Lawrence 2015-12-27 01:34:26 CET
mga5  i586  Mate

Managed to get the old laptop running and up-to-date.  Could not get Bluetooth running before the update but it connected fine to my Bose SLIII speaker after the update.

So it is fine for both architectures.  Validating this.
Len Lawrence 2015-12-27 01:34:52 CET

Whiteboard: MGA5-64-OK => MGA5-64-OK MGA5-32-OK

Len Lawrence 2015-12-27 01:35:07 CET

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Rémi Verschelde 2015-12-28 13:27:18 CET

Whiteboard: MGA5-64-OK MGA5-32-OK => MGA5-64-OK MGA5-32-OK advisory

Comment 11 Mageia Robot 2015-12-28 20:24:41 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0491.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.