CVE-2023-27349: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/bluezto a version that resolves this vulnerability.Fixed in 5.48-0ubuntu3.9+ - Upgrade
Upgrade
ubuntu/bluezto a version that resolves this vulnerability.Fixed in 5.53-0ubuntu3.8 - Upgrade
Upgrade
ubuntu/bluezto a version that resolves this vulnerability.Fixed in 5.64-0ubuntu1.3 - Upgrade
Upgrade
ubuntu/bluezto a version that resolves this vulnerability.Fixed in 5.68-1 - Upgrade
Upgrade
ubuntu/bluezto a version that resolves this vulnerability.Fixed in 5.37-0ubuntu5.3+ - Upgrade
Upgrade
debian/bluezto a version that resolves this vulnerability.Fixed in 5.66-1+deb12u2Fixed in 5.77-1 - Upgrade
Upgrade
redhat/bluezto a version that resolves this vulnerability.Fixed in 5.67
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27349?
CVE-2023-27349 is a critical vulnerability that allows remote code execution via Bluetooth, requiring user interaction to exploit.
How do I fix CVE-2023-27349?
To fix CVE-2023-27349, update the BlueZ package to versions 5.48-0ubuntu3.9+, 5.53-0ubuntu3.8, 5.64-0ubuntu1.3, 5.68-1, or ensure you are on a patched version for your distribution.
Who is affected by CVE-2023-27349?
Users of certain BlueZ versions across various Linux distributions such as Ubuntu, Debian, and Red Hat are affected by CVE-2023-27349.
What kind of attack can be executed using CVE-2023-27349?
CVE-2023-27349 allows attackers to execute arbitrary code remotely through a Bluetooth connection.
Is user interaction required to exploit CVE-2023-27349?
Yes, user interaction is required for an attacker to successfully exploit CVE-2023-27349.