CVE-2023-27349
Publication date 3 May 2024
Last updated 24 July 2024
Ubuntu priority
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
Status
Package | Ubuntu Release | Status |
---|---|---|
bluez | 24.04 LTS noble |
Not affected
|
22.04 LTS jammy |
Fixed 5.64-0ubuntu1.3
|
|
20.04 LTS focal |
Fixed 5.53-0ubuntu3.8
|
|
18.04 LTS bionic |
Fixed 5.48-0ubuntu3.9+esm2
|
|
16.04 LTS xenial |
Fixed 5.37-0ubuntu5.3+esm4
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProReferences
Related Ubuntu Security Notices (USN)
- USN-6809-1
- BlueZ vulnerabilities
- 5 June 2024