Slackwarearm-14.2 ChangeLog (2017-09-17)
Sun Sep 17 08:08:08 UTC 2017
Packages
Upgraded
- patches/packages/bluez-5.47-arm-1_slack14.2.txz
Fixed an information disclosure vulnerability which allows remote attackers
to obtain sensitive information from the bluetoothd process memory. This
vulnerability lies in the processing of SDP search attribute requests.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000250
(* Security fix *) - patches/packages/kernel-firmware-20170917git-noarch-1_slack14.2.txz
- patches/packages/linux-4.4.88/*
This update fixes the security vulnerability known as “BlueBorne”.
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at
Linux kernel version 3.3-rc1 is vulnerable to a stack overflow in
the processing of L2CAP configuration responses resulting in remote
code execution in kernel space.
For more information, see:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000251
https://www.armis.com/blueborne
(* Security fix *)