CVE-2023-50230
published 2024-05-03CVE-2023-50230: BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute…
PriorityP348high8CVSS 3.1
AVAACLPRNUIRSUCHIHAH
EPSS
1.49%
71.3th percentile
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.
The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20938.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u2 | 5.55-3.1+deb11u2 |
| bluez | bluez | >= 0 < 5.66-1+deb12u2 | 5.66-1+deb12u2 |
| bluez | bluez | >= 0 < 5.70-1 | 5.70-1 |
| bluez | bluez | >= 0 < 5.70-1 | 5.70-1 |
| bluez | bluez | >= 5.66 < 5.70 | 5.70 |
| debian | bluez | < bluez 5.66-1+deb12u2 (bookworm) | bluez 5.66-1+deb12u2 (bookworm) |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.0HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-50230: BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
osv·2024-05-03·CVSS 8.0
CVE-2023-50230 [HIGH] CVE-2023-50230: BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20938.
GHSA
GHSA-w9r2-6h22-p3p7: BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
ghsa_unreviewed·2024-05-03
CVE-2023-50230 [HIGH] CWE-122 GHSA-w9r2-6h22-p3p7: BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.
The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20938.
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2025-01-22
CVE-2023-50229 BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: BlueZ could be made to run programs as an administrator if it connected to
a malicious Bluetooth device.
Lucas Leong discovered that BlueZ incorrectly handled the Phone Book Access
profile. If a user were tricked into connecting to a malicious Bluetooth
device, a remote attacker could possibly use this issue to execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bluez: phone book access profile heap-based buffer overflow remote code execution vulnerability
vendor_redhat·2024-05-03·CVSS 8.0
CVE-2023-50230 [HIGH] CWE-122 bluez: phone book access profile heap-based buffer overflow remote code execution vulnerability
bluez: phone book access profile heap-based buffer overflow remote code execution vulnerability
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.
The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20938.
A flaw was found within the handling of
Debian
CVE-2023-50230: bluez - BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution...
vendor_debian·2023·CVSS 8.0
CVE-2023-50230 [HIGH] CVE-2023-50230: bluez - BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution...
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20938.
Scope: local
bookworm: resolved (fixed in 5.66-1+deb12u2)
bullseye: resolved (fixed in 5.55-3.1+deb11u2)
forky: resolved (fixed in 5.70-1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/bluez/bluez/commit/5ab5352531a9cc7058cce569607f3a6831464443https://www.zerodayinitiative.com/advisories/ZDI-23-1812/https://github.com/bluez/bluez/commit/5ab5352531a9cc7058cce569607f3a6831464443https://lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-23-1812/
2024-05-03
Published