MGASA-2023-0353

Source
https://advisories.mageia.org/MGASA-2023-0353.html
Import Source
https://advisories.mageia.org/MGASA-2023-0353.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0353
Related
Published
2023-12-20T17:21:01Z
Modified
2023-12-20T17:07:14Z
Summary
Updated bluez packages fix a security vulnerability
Details

This update fixes the following security issue. Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access (CVE-2023-45866).

References
Credits

Affected packages

Mageia:9 / bluez

Package

Name
bluez
Purl
pkg:rpm/mageia/bluez?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.70-1.mga9

Ecosystem specific

{
    "section": "core"
}