Slackwarearm-14.2 ChangeLog (2017-09-17)

Sun Sep 17 08:08:08 UTC 2017

  • patches/packages/bluez-5.47-arm-1_slack14.2.txz
    Fixed an information disclosure vulnerability which allows remote attackers
    to obtain sensitive information from the bluetoothd process memory. This
    vulnerability lies in the processing of SDP search attribute requests.
    For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000250
    (* Security fix *)
  • patches/packages/kernel-firmware-20170917git-noarch-1_slack14.2.txz
  • patches/packages/linux-4.4.88/*
    This update fixes the security vulnerability known as “BlueBorne”.
    The native Bluetooth stack in the Linux Kernel (BlueZ), starting at
    Linux kernel version 3.3-rc1 is vulnerable to a stack overflow in
    the processing of L2CAP configuration responses resulting in remote
    code execution in kernel space.
    For more information, see:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000251
    https://www.armis.com/blueborne
    (* Security fix *)
  • news/2017/09/17/slackwarearm-14.2-changelog.txt
  • Last modified: 4 years ago
  • by Giuseppe Di Terlizzi