CVE-2018-16265: Medium severity tizen vulnerability
The bt/btcore system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16265?
CVE-2018-16265 is a vulnerability in the bt/bt_core system service in Tizen that allows an unprivileged process to create a system user interface and control the Bluetooth pairing process due to improper D-Bus security policy configurations.
Which versions of Tizen are affected by CVE-2018-16265?
Tizen versions before 5.0 M1 and Tizen-based firmwares, including Samsung Galaxy Gear series, are affected by CVE-2018-16265.
What is the severity of CVE-2018-16265?
The severity of CVE-2018-16265 is medium with a CVSS score of 6.5.
How can I fix CVE-2018-16265?
To fix CVE-2018-16265, update to Tizen version 5.0 M1 or later, and apply any patches provided by the vendor.
Where can I find more information about CVE-2018-16265?
You can find more information about CVE-2018-16265 on the following references: [1][2]