GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Nov 11, 2020 9:26 am Post subject: [ GLSA 202011-11 ] Blueman |
|
|
Gentoo Linux Security Advisory
Title: Blueman: Local privilege escalation (GLSA 202011-11)
Severity: high
Exploitable: local
Date: 2020-11-11
Bug(s): #751556
ID: 202011-11
Synopsis
A privilege escalation vulnerability has been discovered in
Blueman.
Background
Blueman is a simple and intuitive GTK+ Bluetooth Manager.
Affected Packages
Package: net-wireless/blueman
Vulnerable: < 2.1.4
Unaffected: >= 2.1.4
Architectures: All supported architectures
Description
Where Polkit is not used and the default permissions have been changed
on a specific rule file, control of a local DHCP daemon may be possible.
Impact
A local attacker may be able to achieve root privilege escalation.
Workaround
There is no known workaround at this time.
Resolution
All Blueman users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-wireless/blueman-2.1.4"
|
References
CVE-2020-15238 |
|