Mageni can help you to save time and money
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. Mageni is used by companies of all sizes. You will love Mageni's powerful features and ease of use. No registration or credit card is required.
Download Now
Debian: Security Advisory for bluez (DSA-4647-1)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
The remote host is missing an update for the 'bluez' package(s) announced via the DSA-4647-1 advisory.
Insight
Insight
It was reported that the BlueZ's HID and HOGP profile implementations don't specifically require bonding between the device and the host. Malicious devices can take advantage of this flaw to connect to a target host and impersonate an existing HID device without security or to cause an SDP or GATT service discovery to take place which would allow HID reports to be injected to the input subsystem from a non-bonded source.
Affected Software
Affected Software
'bluez' package(s) on Debian Linux.
Detection Method
Detection Method
Checks if a vulnerable package version is present on the target host.
Solution
Solution
For the HID profile an new configuration option (ClassicBondedOnly) is introduced to make sure that input connections only come from bonded device connections. The options defaults to false to maximize device compatibility. For the oldstable distribution (stretch), this problem has been fixed in version 5.43-2+deb9u2. For the stable distribution (buster), this problem has been fixed in version 5.50-1.2~deb10u1. We recommend that you upgrade your bluez packages.
Common Vulnerabilities and Exposures (CVE)
References
Automate with a few clicks your vulnerability scanning, assessment and management process
Automate with a few clicks your vulnerability scanning, assessment and management process
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. No registration or credit card is required. Mageni Community Edition is fast, powerful, free, and open-source. Download it now and Mageni will find your vulnerabilities before they are exploited by hackers.
1. Download Multipass
2. Launch a multipass instance
3. Install Mageni
1. If you don’t have it already, install Brew. Then, to install Multipass simply execute:
2. Launch a multipass instance
2. Install Mageni
1. Download the installer for Windows
2. Ensure your network is private
3. Run the installer
4. Launch a multipass instance
5. Log into the multipass instance
6. Install Mageni