Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.
References
Link | Resource |
---|---|
https://launchpad.net/bugs/1884738 | Issue Tracking Third Party Advisory |
https://ubuntu.com/USN-4519-1 | Third Party Advisory |
https://launchpad.net/bugs/1884738 | Issue Tracking Third Party Advisory |
https://ubuntu.com/USN-4519-1 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:06
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.6
v3 : 5.3 |
References | () https://launchpad.net/bugs/1884738 - Issue Tracking, Third Party Advisory | |
References | () https://ubuntu.com/USN-4519-1 - Third Party Advisory |
Information
Published : 2020-11-19 03:15
Updated : 2024-11-21 05:06
NVD link : CVE-2020-15710
Mitre link : CVE-2020-15710
CVE.ORG link : CVE-2020-15710
JSON object : View
Products Affected
pulseaudio_project
- pulseaudio
canonical
- ubuntu_linux
CWE
CWE-415
Double Free