CVE-2021-3588 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Information disclosure |
| Description | A security issue has been found in BlueZ before version 5.56. The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2061 | bluez | 5.55-3 | 5.56-1 | Medium | Fixed |
| References |
|---|
https://github.com/bluez/bluez/issues/70 https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?h=5.56&id=3a40bef49305f8327635b81ac8be52a3ca063d5a |