Heap-based Buffer Overflow Remote Code Execution Vulnerability in BlueZ Phone Book Access Profile
CVE-2023-51596
7.1HIGH
What is CVE-2023-51596?
A vulnerability exists in the BlueZ Phone Book Access Profile that can lead to remote code execution. This issue arises due to insufficient validation of the length of data provided by users, which is copied into a fixed-length heap-based buffer. Network-adjacent attackers can exploit this flaw by connecting to a compromised Bluetooth device, allowing them to execute arbitrary code within the context of root. It is crucial for users to understand the risks involved with connecting to unknown Bluetooth devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BlueZ 5.66
References
CVSS V3.0
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
