[Git][security-tracker-team/security-tracker][master] CVE-2018-10910,bluez: Minor issue, no-dsa for Jessie.

Markus Koschany apo at debian.org
Sat Aug 18 18:46:23 BST 2018


Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
def82dd6 by Markus Koschany at 2018-08-18T17:39:24Z
CVE-2018-10910,bluez: Minor issue, no-dsa for Jessie.

In gnome-bluetooth <= 3.26 the D-Bus calls were synchronous, DiscoverableTimeout
would not be set if Discoverable was set

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -11473,6 +11473,7 @@ CVE-2018-10911
 CVE-2018-10910 [ailure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices]
 	RESERVED
 	- bluez <unfixed>
+	[jessie] - bluez <no-dsa> (Minor issue because in gnome-bluetooth <= 3.26 the D-Bus calls were synchronous and thus the issue in bluez will have no actual affect)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1606203
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1602985
 	NOTE: Bug in src:bluez itself and would need fixing there, but it is workaroundable in



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/def82dd6128c735aa18a007f5b197e6c8ed2eba6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/def82dd6128c735aa18a007f5b197e6c8ed2eba6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180818/295df82e/attachment.html>


More information about the debian-security-tracker-commits mailing list