CVE-2022-39176: High severity BlueZ BlueZ vulnerability
Published Sep 2, 2022
·Updated
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate paramslen.
Affected Software
4 affected components
BlueZ BlueZ<5.59
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Sep 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-39176?
CVE-2022-39176 is a vulnerability in BlueZ before version 5.59 that allows physically proximate attackers to obtain sensitive information.
2
How does CVE-2022-39176 affect BlueZ?
CVE-2022-39176 affects BlueZ versions before 5.59.
3
What is the severity of CVE-2022-39176?
The severity of CVE-2022-39176 is high with a CVSS score of 8.8.
4
How can an attacker exploit CVE-2022-39176?
An attacker can exploit CVE-2022-39176 by being physically proximate to the target device and obtaining sensitive information.
5
How to fix CVE-2022-39176?
To fix CVE-2022-39176, update BlueZ to version 5.59 or later.