Bug 24482 - bluez new security issue CVE-2016-9918
Summary: bluez new security issue CVE-2016-9918
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-03-08 22:32 CET by David Walser
Modified: 2019-11-25 20:57 CET (History)
2 users (show)

See Also:
Source RPM: bluez-5.45-2.2.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2019-03-08 22:32:37 CET
SUSE has issued an advisory on February 28:
http://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html

I don't know if we've fixed this issue.
David Walser 2019-03-09 02:24:51 CET

Assignee: bugsquad => shlomif

Comment 1 David GEIGER 2019-03-28 06:52:59 CET
I looked at this security issue but I don't found any fixes for this one in current 5.45 release, seems it is fixed since 5.44 release.

CC: (none) => geiger.david68210

Comment 2 David Walser 2019-04-25 00:15:47 CEST
I'm not sure about that, it looks like SUSE had to patch 5.48 for this:
http://lists.suse.com/pipermail/sle-security-updates/2019-April/005283.html
Comment 3 Mike Rambo 2019-11-06 21:22:38 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
Status: NEW => RESOLVED
CC: (none) => mrambo

Comment 4 David Walser 2019-11-25 20:57:22 CET
I suspect CVE-2016-9797 CVE-2016-9798 CVE-2016-9802 CVE-2016-9917, fixed in:
https://lists.opensuse.org/opensuse-updates/2019-05/msg00171.html

are a similar situation.  Hopefully the fixes are already in 5.50.

Note You need to log in before you can comment on or make changes to this bug.