VDB
BDU%3A2024-01454
BDU%3A2024-01454
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость реализации протокола AVRCP стека протоколов Bluetooth для ОС Linux BlueZ, позволяющая нарушителю выполнить произвольный код с правами root
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., ООО «Ред Софт», ООО «РусБИТех-Астра», BlueZ Project, ООО «НЦПР» | SUSE Linux Enterprise Server for SAP Applications, OpenSUSE Leap, Suse Linux Enterprise Server, SUSE Linux Enterprise Software Development Kit, SUSE OpenStack Cloud, SUSE Linux Enterprise Workstation Extension, openSUSE Tumbleweed, SUSE CaaS Platform, SUSE Linux Enterprise High Performance Computing, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, SUSE Linux Enterprise Module for Desktop Applications, SUSE Linux Enterprise Micro, openSUSE Leap Micro, SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Module for Basesystem, BlueZ, МСВСфера |
Timeline
- Feb 20, 2024 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=f54299a850676d92c3dafd83e9174fcfe420ccc9 url
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-19908/ url
- https://www.suse.com/security/cve/CVE-2023-27349.html url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0114SE18MD url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2024:9413?lang=ru url