Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-62224
HistorySep 06, 2022 - 12:00 a.m.

BlueZ input validation error vulnerability

2022-09-0600:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
bluez
bluetooth protocol
input validation error
vulnerability
avrcp.c
attacker
sensitive information
cnvd

EPSS

0.001

Percentile

29.8%

BlueZ is a Bluetooth protocol stack written in C, which is primarily used to provide support for the core Bluetooth layer and protocol. versions prior to BlueZ 5.59 have an input validation error vulnerability that stems from the failure of the profiles/audio/avrcp.c component to validate params_len, which can be exploited by an attacker to gain access to sensitive information.