Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39176


BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.


Published

2022-09-02T04:15:11.427

Last Modified

2024-11-21T07:17:43.200

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bluez bluez < 5.59 Yes
Operating System canonical ubuntu_linux 18.04 Yes
Operating System canonical ubuntu_linux 20.04 Yes
Operating System debian debian_linux 10.0 Yes

References