it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5584-1] bluez security update
- Date: Thu, 21 Dec 2023 19:46:41 +0000
- List-archive: https://lists.debian.org/msgid-search/E1rGP0D-0065nG-Uy AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=OITU15toYI8C/JfWAjzbhIDenZ/tbjfpNljn7TIOLlA=; b=tO NIsQWYF/W71k3ISPyO/XX3a6uB9f/tY7X9ivycvGqG12n3kwKSv9AOjALc433Zs1qYvparhtpY4MO vpyTZ7eejei+hrwUjSGRSXLOJGr7/vo9QgoPC0UhKn3ukd3kKWhD5vAIVE+tXS6MBPjsc6Vo9qFDj U6hnZsFPY62LO6W/wh0QhJDOYlwk1srQ+qT/UhPvIKwJZdK+phwQOx78g001y3mhshg1aAc/YKISk 467H2CAyWtVP/3XOZStl1I2hZsC/yBX7eL5jq6LBk0DUAWl3fH/91FUFC1I42ye55nVvgJjsy9LPP +9j/TnAVIUanSN4NiK5rSZzz/RRY5ZRg==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Thu, 21 Dec 2023 19:47:17 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <zYfFKPyVHYD.A.FqH.FZJhlB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5584-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
December 21, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : bluez
CVE ID : CVE-2023-45866
Debian Bug : 1057914
It was reported that the BlueZ's HID profile implementation is not
inline with the HID specification which mandates the use of Security
Mode 4. The HID profile configuration option ClassicBondedOnly now
defaults to "true" to make sure that input connections only come from
bonded device connections.
For the oldstable distribution (bullseye), this problem has been fixed
in version 5.55-3.1+deb11u1.
For the stable distribution (bookworm), this problem has been fixed in
version 5.66-1+deb12u1.
We recommend that you upgrade your bluez packages.
For the detailed security status of bluez please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/bluez
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWElXhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Qbdw/+Ly8+kB39iFkiQiFluySzb1mPvYHz0RBYx5aa8iLhWU6SuuZwFGv1ZNTf
r16whtZOmBGYPDjJrRbksd01rNxIlwW8jaNPCOiDySYqrw3Ni0cbWRYrtNSjzOYJ
cwoPg+4OYEiY+0HkAuTaAfctD5Nyf6sIN2dMsy3VERxZAlRFMUElAVn2obhRoW3P
VtQHfVsedGcVsmxHS72MnXIEBYhFu9Q+lA80qfteiPBnQUFo41DeV1ar1uGBhDWG
qwkl+8+etRYhnLMnX361Hd+5eVAC8IIQQaFR+5lfq7VydIcDcV2gpENOxNj4G3T1
TSJ+ts6BX9BSuPVXFckymid71bbUJ+1r/IpvA8nlc+UIDTPmpZygijohMkjOpuNH
kwkPVuRNmOAH6/umh7auZn5donXaPA8k303EUvaMNpGxfmD3jxdLsDwrrE/qRtGv
kPCV67y0N6ZaN1d8wxuIcQ4aiQVAgNlmi9hhAfYhhhdt3y/oGcqMT2iUPQIla3Wj
sWRUYt8mTcZdG2g00WBj+DTh0EuUwd9ILYPfSK+zWf+ikQ1+LrQvfVEMD1ejWmIg
QI6vxwN9wiim9PydlAbtlsQ4vb/246MPuWbXcRS3omW3CvK86i0GpSVvpjrr2DmB
pQ4rYr6bFcVINzLr79lz5GMGIpuShCllrtLkXofyfhinvNthKZs=
=DXXJ
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5584-1] bluez security update, Salvatore Bonaccorso, 21.12.2023
Archiv bereitgestellt durch MHonArc 2.6.19+.