Heap-based Buffer Overflow Remote Code Execution Vulnerability in BlueZ Phone Book Access Profile
CVE-2023-51596
7.1HIGH
What is CVE-2023-51596?
A vulnerability exists in the BlueZ Phone Book Access Profile that can lead to remote code execution. This issue arises due to insufficient validation of the length of data provided by users, which is copied into a fixed-length heap-based buffer. Network-adjacent attackers can exploit this flaw by connecting to a compromised Bluetooth device, allowing them to execute arbitrary code within the context of root. It is crucial for users to understand the risks involved with connecting to unknown Bluetooth devices.
Affected Version(s)
BlueZ 5.66
