Hide Forgot
A heap-based buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash. PoC can be found in following report: https://www.spinics.net/lists/linux-bluetooth/msg68892.html
Created kf5-bluez-qt tracking bugs for this issue: Affects: fedora-all [bug 1403885] Affects: epel-7 [bug 1403887]
Created bluez tracking bugs for this issue: Affects: fedora-all [bug 1403883]
Created bluez-hcidump tracking bugs for this issue: Affects: fedora-all [bug 1403886]