{"id":"MGASA-2020-0152","summary":"Updated bluez packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\n\nA bug in Bluez may allow for the Bluetooth Discoverable state being\nset to on when no Bluetooth agent is registered with the system. This\nsituation could lead to the unauthorized pairing of certain Bluetooth\ndevices without any form of authentication. Versions before bluez 5.51\nare vulnerable. (CVE-2018-10910)\n\nImproper access control in subsystem for BlueZ before version 5.54 may\nallow an unauthenticated user to potentially enable escalation of\nprivilege and denial of service via adjacent access. (CVE-2020-0556)\n","modified":"2026-04-16T04:43:35.806450814Z","published":"2020-04-02T22:48:49Z","upstream":["CVE-2018-10910","CVE-2020-0556"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0152.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25969"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2020/03/12/4"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2020/03/13/2"},{"type":"WEB","url":"https://www.debian.org/security/2020/dsa-4647"},{"type":"WEB","url":"https://usn.ubuntu.com/4311-1/"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2020:1101"}],"affected":[{"package":{"name":"bluez","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/bluez?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.54-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0152.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}