[Git][security-tracker-team/security-tracker][master] Track additional CVEs for bluetooth issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 27 07:45:22 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8525f02c by Salvatore Bonaccorso at 2021-05-27T08:45:03+02:00
Track additional CVEs for bluetooth issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47188,20 +47188,35 @@ CVE-2020-26562
 CVE-2020-26561 (** UNSUPPORTED WHEN ASSIGNED ** Belkin LINKSYS WRT160NL 1.0.04.002_US_ ...)
 	NOT-FOR-US: Belkin
 CVE-2020-26560 (Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0. ...)
-	TODO: check
+	- linux <unfixed>
+	NOTE: https://kb.cert.org/vuls/id/799380
+	NOTE: https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/impersonation-mesh/
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1959994
 CVE-2020-26559 (Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0. ...)
-	TODO: check
+	- linux <unfixed>
+	NOTE: https://kb.cert.org/vuls/id/799380
+	NOTE: https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/authvalue-leak/
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1960011
 CVE-2020-26558 (Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification ...)
 	- linux <unfixed>
 	NOTE: https://kb.cert.org/vuls/id/799380
 	NOTE: https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/passkey-entry/
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1918602
 CVE-2020-26557 (Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may perm ...)
-	TODO: check
+	- linux <unfixed>
+	NOTE: https://kb.cert.org/vuls/id/799380
+	NOTE: https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/predicatable-authvalue/
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1960009
 CVE-2020-26556 (Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may perm ...)
-	TODO: check
+	- linux <unfixed>
+	NOTE: https://kb.cert.org/vuls/id/799380
+	NOTE: https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/malleable/
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1960012
 CVE-2020-26555 (Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specificati ...)
-	TODO: check
+	- linux <unfixed>
+	NOTE: https://kb.cert.org/vuls/id/799380
+	NOTE: https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/impersonation-pin-pairing/
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1918601
 CVE-2020-26554 (REDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML  ...)
 	NOT-FOR-US: REDDOXX MailDepot
 CVE-2020-26553 (An issue was discovered in Aviatrix Controller before R6.0.2483. Sever ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8525f02c5885351befadcaeeef53670bf37c443b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8525f02c5885351befadcaeeef53670bf37c443b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210527/2d65dd22/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list